Skip to content

Conversation

@n1v0lg
Copy link
Contributor

@n1v0lg n1v0lg commented Apr 1, 2025

Backports the following commits to 8.x:

This PR makes authorization denial messages account for privileges that
grant access to the failure store. This is a minimal implementation that
only displays information around failure store privileges for requests
that include concrete names with the `::failures` selector. This avoids
including irrelevant information in regular non-failures requests. We
can improve on this in follow ups. 

Closes: ES-11158
@n1v0lg n1v0lg added :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC >non-issue auto-merge-without-approval Automatically merge pull request when CI checks pass (NB doesn't wait for reviews!) backport serverless-linked Added by automation, don't add manually Team:Security Meta label for security team labels Apr 1, 2025
@n1v0lg n1v0lg removed the serverless-linked Added by automation, don't add manually label Apr 1, 2025
@elasticsearchmachine elasticsearchmachine merged commit c7a85ae into elastic:8.x Apr 1, 2025
20 checks passed
@n1v0lg n1v0lg deleted the backport/8.x/pr-125757 branch April 1, 2025 13:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-merge-without-approval Automatically merge pull request when CI checks pass (NB doesn't wait for reviews!) backport >non-issue :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC Team:Security Meta label for security team v8.19.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants