Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Clear Dev Tools when logging out a user with X-Pack installed to Kibana #17658

Open
djptek opened this issue Apr 11, 2018 · 2 comments
Open

Clear Dev Tools when logging out a user with X-Pack installed to Kibana #17658

djptek opened this issue Apr 11, 2018 · 2 comments
Labels
Feature:Console Dev Tools Console Feature impact:low Addressing this issue will have a low level of impact on the quality/strength of our product. loe:small Small Level of Effort Team:Kibana Management Dev Tools, Index Management, Upgrade Assistant, ILM, Ingest Node Pipelines, and more

Comments

@djptek
Copy link

djptek commented Apr 11, 2018

When logging out a user from Kibana and then logging in as a different user using the same Browser, "Dev Tools" exposes any commands cached from the previous user. Even though the new user may not have privileges to run these commands, there still exists potential for inadvertent disclosure of information, hence the security tag. While it is really useful in a single-user scenario to have that cache, I'd suggest some (configurable) mechanism to be able to clear this.

@djptek djptek added the Team:Security Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more! label Apr 11, 2018
@tylersmalley tylersmalley added Feature:Console Dev Tools Console Feature :Management labels Apr 11, 2018
@cjcenizal cjcenizal added Team:Kibana Management Dev Tools, Index Management, Upgrade Assistant, ILM, Ingest Node Pipelines, and more and removed :Management DO NOT USE labels Jun 14, 2019
@elasticmachine
Copy link
Contributor

Pinging @elastic/es-ui

@cjcenizal
Copy link
Contributor

This could be addressed by #17888 (comment).

@cjcenizal cjcenizal changed the title Feature request: clear Dev Tools when logging out a user with X-Pack installed to Kibana Clear Dev Tools when logging out a user with X-Pack installed to Kibana Oct 1, 2019
@exalate-issue-sync exalate-issue-sync bot added impact:low Addressing this issue will have a low level of impact on the quality/strength of our product. loe:small Small Level of Effort labels Aug 5, 2021
@legrego legrego removed the Team:Security Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more! label Jan 25, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature:Console Dev Tools Console Feature impact:low Addressing this issue will have a low level of impact on the quality/strength of our product. loe:small Small Level of Effort Team:Kibana Management Dev Tools, Index Management, Upgrade Assistant, ILM, Ingest Node Pipelines, and more
Projects
None yet
Development

No branches or pull requests

5 participants