# Action \[indices:data/read/search\] is unauthorized for user

**URL:** <https://discuss.elastic.co/t/action-indices-data-read-search-is-unauthorized-for-user/194789>\
**Category:** Elasticsearch\
**Created:** [August 12, 2019, 5:49am UTC](https://discuss.elastic.co/t/action-indices-data-read-search-is-unauthorized-for-user/194789 "2019-08-12T05:49:50Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jhonko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jhonko/32/48640_2.png) [@jhonko](https://discuss.elastic.co/u/jhonko)\
**Post date:** [August 12, 2019, 5:49am UTC](https://discuss.elastic.co/t/action-indices-data-read-search-is-unauthorized-for-user/194789/1 "2019-08-12T05:49:50Z")

</div>

Hello!

I'm currently evaluating Elastic Stack and I have problems related to REST API authorization. I'm not sure if I'm doing something wrong or if there's a bug is Elasticsearch.

I have setup OIDC SSO successfully (using our custom OIDC standards compliant IdP) and I'm able to get access token from Elasticsearch \_security/oidc/authenticate endpoint. When I try to use it to invoke kibana\_sample\_data\_ecommerce/\_search endpoint, I get following error

> The remote server returned an error: (403) Forbidden.. Call: Status code 403 from: POST /kibana\_sample\_data\_ecommerce/\_search?typed\_keys=true. ServerError: Type: security\_exception Reason: "action [indices:data/read/search] is unauthorized for user [admin]"

So it seems that I can authenticate, but authorization fails.

Authenticated user is "admin" like the error message says.  
User has access to kibana\_sample\_data\_ecommerce index because I can log in to Kibana as that user and successfully query data using Kibana dev tools.  
NEST library is used for search query.  
Access token is provided in Authorization header as a Bearer token.  
Data is from Kibana eCommerce sample data.

Our IdP returns a _profile claim_ which value I use to assign roles to the authenticated user. Role mapping looks like this

```
PUT /_security/role_mapping/testrole
{
  "roles": ["kibana_user", "testrole"],
  "enabled": true,
  "rules": { "all": [
        { "field": { "realm.name": "oidc1" } },
        { "field": { "groups": "testrole" } }
  ] }
}

```

Elasticsearch.yml has following configuration

```
xpack.security.authc.realms.oidc.oidc1:
  order: 2
  ...
  rp.requested_scopes: "openid profile email"
  ...
  claims.principal: preferred_username
  claims.mail: email
  claims.groups: profile

```

And the actual "testrole" role has kibana\_sample\_data\_ecommerce index with "read" and "view\_index\_metadata" privileges.

Code part using NEST (C#)

```
var settings = new ConnectionSettings(new Uri("http://localhost:9200"))
	.GlobalHeaders(new NameValueCollection
	{
		{ "Authorization", $"Bearer {elasticOidcAuthenticateResponse.AccessToken}" }
	})
	.DefaultIndex("kibana_sample_data_ecommerce");

var elasticClient = new ElasticClient(settings);

// BUG: This fails because of the following error.
// The remote server returned an error: (403) Forbidden... 
var elasticSearchResponse = elasticClient.Search<dynamic>();

```

Any ideas what could be wrong?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 9, 2019, 5:49am UTC](https://discuss.elastic.co/t/action-indices-data-read-search-is-unauthorized-for-user/194789/2 "2019-09-09T05:49:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
