New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Odd script config behavior #7088
Comments
Hi @mal, I'm trying to reproduce this issue with your example, I actually get a different exception due to Can you give me the full stacktrace of the exception? Also, when you put the script in |
Aha, it fails to compile so I guess it doesn't get found and ES assumes
I tried adding
|
How did you add it to the Also, going forward, looking at the javadoc I don't see any reason why |
I added the following line to
|
@mal ahh okay, this is because the whitelist has to be entirely enumerated (it replaces the default whitelist, doesn't add to it), so adding that line removed the other whitelisted classes (like I think this does need to be clarified in the docs, and it would be nice to have the functionality of both (replacing and adding to the whitelist). |
Opened #7089 for adding the |
Ahh ok, is there any disadvantage to disabling the sandbox given dynamic scripting is already off and that an attacker would already need root access to edit installed scripts? If not I'll probably just do that for now. Thanks for your help! |
Yea, you can do this, disable the sandbox and since dynamic scripting is disabled by default, you'll just have to put it on disk. I'll treat this issue as an issue to update the docs, thanks for the report! |
Also clarify in the docs that changing the whitelist/blacklist settings replace the list, they don't add to it. Fixes elastic#7089 Fixes elastic#7088
Just upgraded from
1.2.1
with the groovy plugin to1.3.1
(plugin removed) and I'm seeing some weird behaviour when trying to use my installed scripts, I've written a test script here.Settings
Query
Script
Results
Which, while true, shouldn't apply since I'm trying to run a script stored on disk ...
The text was updated successfully, but these errors were encountered: