Skip to content

atlassian_confluence: bound the Cloud group-name split in Painless - #21671

Merged
kcreddy merged 3 commits into
elastic:mainfrom
kcreddy:atlassian_confluence-audit-regex-limit
Sep 29, 2026
Merged

kcreddy merged 3 commits into
elastic:mainfrom
kcreddy:atlassian_confluence-audit-regex-limit

Conversation

@kcreddy

@kcreddy kcreddy commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Proposed commit message

atlassian_confluence: bound the Cloud group-name split in Painless

The ECS user fields script splits Cloud audit group names rendered as
'<groupName>:<groupId>' using an unanchored greedy regex,
(.+):(<uuid>)$. When atlassian_cloud is enabled and a group name does
not match that format, matcher.find() backtracks across the whole name
and can exceed the Painless regex limit. A 68-character name observed
in customer data ('<groupId>; User: <accountId>' for a membership
event) fails with "Regular expression considered too many characters"
(limit factor 6, 409 of 408 characters considered), turning the whole
document into a pipeline_error.

Replace the regex with string operations: find the last ':', check
that a 36-character suffix follows, and validate that suffix with an
anchored full-match UUID pattern. The regex now only ever runs against
a fixed 36-character substring, so the work is bounded regardless of
group-name length. Also guard against a null group name, which
previously raised a NullPointerException from matcher().

Splitting behaviour for '<groupName>:<groupId>' names is unchanged;
the regenerated cloud expected file only gains the new document. Add
the offending event to test-audit-cloud.log to cover the fix on the
configured Cloud path.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

The ECS user fields script splits Cloud audit group names rendered as
'<groupName>:<groupId>' using an unanchored greedy regex,
(.+):(<uuid>)$. When atlassian_cloud is enabled and a group name does
not match that format, matcher.find() backtracks across the whole name
and can exceed the Painless regex limit. A 68-character name observed
in customer data ('<groupId>; User: <accountId>' for a membership
event) fails with "Regular expression considered too many characters"
(limit factor 6, 409 of 408 characters considered), turning the whole
document into a pipeline_error.

Replace the regex with string operations: find the last ':', check
that a 36-character suffix follows, and validate that suffix with an
anchored full-match UUID pattern. The regex now only ever runs against
a fixed 36-character substring, so the work is bounded regardless of
group-name length. Also guard against a null group name, which
previously raised a NullPointerException from matcher().

Splitting behaviour for '<groupName>:<groupId>' names is unchanged;
the regenerated cloud expected file only gains the new document. Add
the offending event to test-audit-cloud.log to cover the fix on the
configured Cloud path.
@kcreddy kcreddy self-assigned this Sep 28, 2026
@kcreddy kcreddy added Integration:atlassian_confluence Atlassian Confluence bugfix Pull request that fixes a bug issue Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Sep 28, 2026
@kcreddy
kcreddy marked this pull request as ready for review September 28, 2026 07:16
@kcreddy
kcreddy requested review from a team as code owners September 28, 2026 07:16
Copilot AI lite review requested due to automatic review settings September 28, 2026 07:16
@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@github-actions

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

A null-name regression case remains uncovered, warranting final human review.

Review effort: Lite
Findings: 1 Low severity

Open (1)
What changed in this PR

Hardens Confluence Cloud audit group-name parsing to prevent Painless regex-limit failures.

Changes:

  • Bounds UUID suffix validation.
  • Handles null group names safely.
  • Adds regression fixtures, version bump, and changelog entry.
File Change
packages/​atlassian_confluence/​manifest.yml Bumps version to 1.35.1.
packages/​atlassian_confluence/​data_stream/​audit/​elasticsearch/​ingest_pipeline/​default.yml Implements bounded parsing and null guarding.
packages/​atlassian_confluence/​data_stream/​audit/​_dev/​test/​pipeline/​test-audit-cloud.log-expected.json Adds expected regression output.
packages/​atlassian_confluence/​data_stream/​audit/​_dev/​test/​pipeline/​test-audit-cloud.log Adds malformed group-name regression input.
packages/​atlassian_confluence/​changelog.yml Documents the bug fix.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@vera-review-bot

Copy link
Copy Markdown

🟢 No issues across the latest commits 042ad0f.

A new commit triggers another review — at most once every 15 minutes. I skip the PR while it's approved or has merge conflicts.

🤖 AI-Generated Review | Vera Review Bot - v0.4.2 | 📚 Knowledge base: integration-skills

⚠️ Automated review — verify suggestions before applying.

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@mergify

mergify Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

This pull request does not currently match the merge queue conditions, so it cannot be queued from here. The box comes back if it matches again.

Copilot AI review requested due to automatic review settings September 29, 2026 05:52
@kcreddy
kcreddy enabled auto-merge (squash) September 29, 2026 05:53

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified.

Review effort: Lite
Findings: None

Resolved since last review (1)

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

✅ All changelog entries have the correct PR link.

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @kcreddy

@kcreddy
kcreddy merged commit f246f90 into elastic:main Sep 29, 2026
14 checks passed
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package atlassian_confluence - 1.35.1 containing this change is available at https://epr.elastic.co/package/atlassian_confluence/1.35.1/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Pull request that fixes a bug issue Integration:atlassian_confluence Atlassian Confluence Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants