-
Notifications
You must be signed in to change notification settings - Fork 338
[Resource Sharing] Allow multiple sharable resource types in single resource index #5713
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Resource Sharing] Allow multiple sharable resource types in single resource index #5713
Conversation
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Darshit Chanpura <[email protected]>
Signed-off-by: Darshit Chanpura <[email protected]>
Signed-off-by: Darshit Chanpura <[email protected]>
Signed-off-by: Darshit Chanpura <[email protected]>
Signed-off-by: Darshit Chanpura <[email protected]>
Signed-off-by: Darshit Chanpura <[email protected]>
Signed-off-by: Darshit Chanpura <[email protected]>
… as protected and fixes share api action to throw 400 on resources not marked as protected Signed-off-by: Darshit Chanpura <[email protected]>
…consume new changes Signed-off-by: Darshit Chanpura <[email protected]>
Signed-off-by: Darshit Chanpura <[email protected]>
Signed-off-by: Darshit Chanpura <[email protected]>
Signed-off-by: Darshit Chanpura <[email protected]>
…ad-safe in resource-plugin-info class Signed-off-by: Darshit Chanpura <[email protected]>
Signed-off-by: Darshit Chanpura <[email protected]>
Signed-off-by: Darshit Chanpura <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
|
I plan to add new integration tests...either in this PR or another that add a second resource type ( |
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
This reverts commit 5b3f561. Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This will be good addition to this new framework and will setup a path to implement linux-style ACLs to allow hierarchical access authorization.
I have left a few comments. PR looks good mostly otherwise.
spi/src/main/java/org/opensearch/security/spi/resources/client/ResourceSharingClient.java
Show resolved
Hide resolved
src/main/java/org/opensearch/security/configuration/DlsFlsValveImpl.java
Outdated
Show resolved
Hide resolved
.../java/org/opensearch/security/resources/api/migrate/MigrateResourceSharingInfoApiAction.java
Outdated
Show resolved
Hide resolved
src/main/java/org/opensearch/security/resources/api/share/ShareRequest.java
Outdated
Show resolved
Hide resolved
src/main/java/org/opensearch/security/resources/ResourceAccessControlClient.java
Show resolved
Hide resolved
src/main/java/org/opensearch/security/resources/ResourceAccessHandler.java
Show resolved
Hide resolved
src/main/java/org/opensearch/security/resources/ResourceAccessHandler.java
Show resolved
Hide resolved
src/main/java/org/opensearch/security/resources/ResourcePluginInfo.java
Outdated
Show resolved
Hide resolved
...a/org/opensearch/sample/resourcegroup/actions/rest/search/SearchResourceGroupRestAction.java
Outdated
Show resolved
Hide resolved
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Craig Perkins <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
thank you for addressing the comments. left a final few. Will approve once addressed.
.../java/org/opensearch/security/resources/api/migrate/MigrateResourceSharingInfoApiAction.java
Outdated
Show resolved
Hide resolved
.../java/org/opensearch/security/resources/api/migrate/MigrateResourceSharingInfoApiAction.java
Outdated
Show resolved
Hide resolved
Signed-off-by: Craig Perkins <[email protected]>
Signed-off-by: Darshit Chanpura <[email protected]>
Description
This PR contains changes to the ResourceAccessControlClient to start to refer to
resourceTypeeverywhere instead ofresourceIndex. Currently, the repo assumes a 1-to-1 relationship between resource type and index, but this should be relaxed to allow multiple resource types in a single index (think dashboards saved objects).Enhancement
Check List
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.