-
Notifications
You must be signed in to change notification settings - Fork 25.6k
Closed
Labels
:Security/AuthenticationLogging in, Usernames/passwords, Realms (Native/LDAP/AD/SAML/PKI/etc)Logging in, Usernames/passwords, Realms (Native/LDAP/AD/SAML/PKI/etc)>bugTeam:SecurityMeta label for security teamMeta label for security team
Description
The tests for security.clear_api_key_cache seems to indicate that ids is optional by allowing to pass an empty string "" for ids.
And therefor the tests assumes whatever builds the url will happily build /_security/api_key//_clear_cache.
This is true for the java test runner but this is not true for the more strict clients.
The spec and the RestAction need to explictly define /_security/api_key/_clear_cache as a valid route to clear all API's.
After a quick peek I suspect the same is true for several other security related (clear_*) API's
Metadata
Metadata
Assignees
Labels
:Security/AuthenticationLogging in, Usernames/passwords, Realms (Native/LDAP/AD/SAML/PKI/etc)Logging in, Usernames/passwords, Realms (Native/LDAP/AD/SAML/PKI/etc)>bugTeam:SecurityMeta label for security teamMeta label for security team