-
Notifications
You must be signed in to change notification settings - Fork 25.6k
Open
Labels
:Security/AuthorizationRoles, Privileges, DLS/FLS, RBAC/ABACRoles, Privileges, DLS/FLS, RBAC/ABAC>breaking>featureTeam:SecurityMeta label for security teamMeta label for security team
Description
Original comment by @tvernum:
We've discussed this a number of times in the past. The current approach of authorising based on aliases was an attempt to offer something a bit like DLS, prior to our proper DLS implementation.
Switching to only authorise on indices would make a lot of the code simpler, but would be a breaking change (and is complicated by license levels, aliases work in Gold, but DLS is in Platinum).
Opening this ticket as a place for discussion.
a03nikki
Metadata
Metadata
Assignees
Labels
:Security/AuthorizationRoles, Privileges, DLS/FLS, RBAC/ABACRoles, Privileges, DLS/FLS, RBAC/ABAC>breaking>featureTeam:SecurityMeta label for security teamMeta label for security team