-
Notifications
You must be signed in to change notification settings - Fork 25.6k
Closed
Labels
:Security/AuthorizationRoles, Privileges, DLS/FLS, RBAC/ABACRoles, Privileges, DLS/FLS, RBAC/ABAC
Description
The API Key actions are under the cluster:admin/xpack/security namespace.
The only cluster privileges that allow access to those actions are manage_security and all, both of which grant far more access than is actually required to create an API Key.
There should be a specific privilege to allow a user to create/delete their own API keys.
bizybot and andresantoniuk
Metadata
Metadata
Assignees
Labels
:Security/AuthorizationRoles, Privileges, DLS/FLS, RBAC/ABACRoles, Privileges, DLS/FLS, RBAC/ABAC