Repository navigation
atlassian_confluence: bound the Cloud group-name split in Painless - #21671
Conversation
The ECS user fields script splits Cloud audit group names rendered as
'<groupName>:<groupId>' using an unanchored greedy regex,
(.+):(<uuid>)$. When atlassian_cloud is enabled and a group name does
not match that format, matcher.find() backtracks across the whole name
and can exceed the Painless regex limit. A 68-character name observed
in customer data ('<groupId>; User: <accountId>' for a membership
event) fails with "Regular expression considered too many characters"
(limit factor 6, 409 of 408 characters considered), turning the whole
document into a pipeline_error.
Replace the regex with string operations: find the last ':', check
that a 36-character suffix follows, and validate that suffix with an
anchored full-match UUID pattern. The regex now only ever runs against
a fixed 36-character substring, so the work is bounded regardless of
group-name length. Also guard against a null group name, which
previously raised a NullPointerException from matcher().
Splitting behaviour for '<groupName>:<groupId>' names is unchanged;
the regenerated cloud expected file only gains the new document. Add
the offending event to test-audit-cloud.log to cover the fix on the
configured Cloud path.
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
✅ Elastic Docs Style Checker (Vale)No issues found on modified lines! The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
A null-name regression case remains uncovered, warranting final human review.
Review effort: Lite
Findings: 1
What changed in this PR
Hardens Confluence Cloud audit group-name parsing to prevent Painless regex-limit failures.
Changes:
- Bounds UUID suffix validation.
- Handles null group names safely.
- Adds regression fixtures, version bump, and changelog entry.
| File | Change |
|---|---|
packages/atlassian_confluence/manifest.yml |
Bumps version to 1.35.1. |
packages/atlassian_confluence/data_stream/audit/elasticsearch/ingest_pipeline/default.yml |
Implements bounded parsing and null guarding. |
packages/atlassian_confluence/data_stream/audit/_dev/test/pipeline/test-audit-cloud.log-expected.json |
Adds expected regression output. |
packages/atlassian_confluence/data_stream/audit/_dev/test/pipeline/test-audit-cloud.log |
Adds malformed group-name regression input. |
packages/atlassian_confluence/changelog.yml |
Documents the bug fix. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
🟢 No issues across the latest commits 042ad0f.
🤖 AI-Generated Review | Vera Review Bot - v0.4.2 | 📚 Knowledge base: integration-skills
|
🚀 Benchmarks reportTo see the full report comment with |
|
This pull request does not currently match the merge queue conditions, so it cannot be queued from here. The box comes back if it matches again. |
|
✅ All changelog entries have the correct PR link. |
💚 Build Succeeded
History
cc @kcreddy |
|
Package atlassian_confluence - 1.35.1 containing this change is available at https://epr.elastic.co/package/atlassian_confluence/1.35.1/ |
Proposed commit message
Checklist
changelog.ymlfile.