20517: Fix for security plugin not working - #5989
Conversation
|
@Deepti24 I think it makes more sense to add this into the existing allowlist in core here: https://github.com/opensearch-project/OpenSearch/blob/521cef17225014e717e16a414aa50b5753fe043b/server/src/main/java/org/opensearch/tasks/Task.java#L85 @sgup432 iirc did you have a similar PR open to allowlist additional headers related to tracing? |
|
@Deepti24 we can actually do this from a plugin as well ActionPlugin.getRestHeaders extension point. |
|
@cwperks I have added relevant changes here as well: opensearch-project/OpenSearch#20819 A new method getTransients is added to ActionPlugin class. We could have reused headers but felt like it would be unclear which fields are transients to recover in security plugin within headers map. Also, responsibility wise both looked different. Do let me know if my understanding is incorrect Also, I am signed some unwanted commits in this PR. Have raised new one with only my signed commits closing this one |
Signed-off-by: Deepti Chauhan <dchauhan3@atlassian.com> Signed-off-by: Deepti24 <chauhan.deepti24@gmail.com>
Signed-off-by: Deepti24 <chauhan.deepti24@gmail.com>
Signed-off-by: Deepti24 <chauhan.deepti24@gmail.com>
Signed-off-by: Deepti24 <chauhan.deepti24@gmail.com>
Signed-off-by: Deepti24 <chauhan.deepti24@gmail.com>
…-project#5995) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Deepti24 <chauhan.deepti24@gmail.com>
Signed-off-by: Deepti24 <chauhan.deepti24@gmail.com>
Signed-off-by: Deepti24 <chauhan.deepti24@gmail.com>
Description
This is the fix for the security plugin issue mentioned here: https://github.com/opensearch-project/opensearch/issues/20517
Problem was that security plugin was using restore method from thread context which is overriding the transients (which store span id as well)
Issues Resolved
https://github.com/opensearch-project/opensearch/issues/20517
Is this a backport? If so, please add backport PR # and/or commits #, and remove
backport-failedlabel from the original PR.Do these changes introduce new permission(s) to be displayed in the static dropdown on the front-end? If so, please open a draft PR in the security dashboards plugin and link the draft PR here
Testing
UNIT TESTS:
Added a unit to see if I set span id in transients and call restore and try to set it again later, I will able to generate traces successfully. To avoid static mocking in junits, I have tested required functionality by creating a mocked scenario. Do let me know if I should use static mocking for the same
MANUAL TESTS:
Steps:
Check List
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.