# Allowed script contexts list

**URL:** <https://discuss.elastic.co/t/allowed-script-contexts-list/195549>\
**Category:** Elasticsearch\
**Created:** [August 16, 2019, 7:02pm UTC](https://discuss.elastic.co/t/allowed-script-contexts-list/195549 "2019-08-16T19:02:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thomas\_Doman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomas_doman/32/11409_2.png) [@Thomas\_Doman](https://discuss.elastic.co/u/Thomas_Doman)\
**Post date:** [August 16, 2019, 7:02pm UTC](https://discuss.elastic.co/t/allowed-script-contexts-list/195549/1 "2019-08-16T19:02:27Z")

</div>

ES: 6.1.1  
NEST: 6.1

We have set our allowed script types to `stored` only. In reading [Allowed Script Contexts](https://www.elastic.co/guide/en/elasticsearch/reference/6.1/modules-scripting-security.html#allowed-script-contexts-setting), it shows a couple of examples of available contexts but I've been unable to find a comprehensive list, let alone precise descriptions of each.

So far, I have discovered by trial and error (literally, the error information that is returned from calls where my scripts are disallowed) what some of the other contexts are such as `filter` and `aggs` but I've also had to add `aggs_execute` which I can't differentiate from `aggs`. Why do I need both? Anyway, I'm assuming there's some good documentation somewhere but I haven't yet discovered it. Can anyone provide me some guidance here?

---

<div class="post-metadata">

**Author:** ![Jack\_Conradson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_conradson/32/47236_2.png) [@Jack\_Conradson](https://discuss.elastic.co/u/Jack_Conradson)\
**Post date:** [August 19, 2019, 4:11pm UTC](https://discuss.elastic.co/t/allowed-script-contexts-list/195549/2 "2019-08-19T16:11:24Z")

</div>

The documentation for this doesn't exist, yet (though, it's being worked on) as unfortunately scripts contexts have only begun to settle into some consistency.

Here is a list of context names in the current version - though, it's not exactly a 1:1 mapping for script usage. This is something we hope to accomplish moving forward.

analysis - AnalysisPredicateScript  
painless\_test - used for the Painless execute API  
interval - IntervalFilterScript  
aggs\_execute - used to execute different aggregations (though, this has been removed from the later versions)  
aggs - used for several different aggregations  
bucket\_aggregation - used for bucket aggregations  
aggregation\_selector - used for bucket aggregations  
field - used for script fields  
filter - used for several different types of filter scripts  
processor\_conditional - used for ingest condition scripts  
ingest - used for ingest processor scripts  
number\_sort - used for scripts that use score and return a numeric value  
score - used for score scripts  
aggs\_combine - metric aggregation combine script  
aggs\_init - metric aggregation init script  
aggs\_map - metric aggregration map script  
aggs\_reduce - metric aggregation reduce script  
script\_heuristic - signficant terms heuristic score script  
similarity - scripts that change how similarity for scoring is done  
similarityWeight - scripts that change the similarity weight for scoring  
string\_sort - sorting script that returns a string  
template - template script typically used by Mustache  
terms\_set - TermsSetQueryScript  
update\_script - scripts used to update documents  
moving-function - scripts used in moving function pipeline aggregations  
xpack\_template - template script for watcher  
watcher\_condition - watcher conditions scripts  
watcher\_transform - watcher transform scripts

I fully appreciate this feature is nebulous and frustrating to use currently.

---

<div class="post-metadata">

**Author:** ![Thomas\_Doman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomas_doman/32/11409_2.png) [@Thomas\_Doman](https://discuss.elastic.co/u/Thomas_Doman)\
**Post date:** [August 19, 2019, 4:50pm UTC](https://discuss.elastic.co/t/allowed-script-contexts-list/195549/3 "2019-08-19T16:50:16Z")

</div>

@Jack_Conradson Thank you very much! I appreciate you clearing things up as much as can be done now and I look forward to seeing it tightened up in the future.

Can you further differentiate `aggs` and `aggs_execute`? I discovered that I had to use both (or possibly `aggs_execute` was the only one I **really** needed).

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [August 20, 2019, 11:42pm UTC](https://discuss.elastic.co/t/allowed-script-contexts-list/195549/4 "2019-08-20T23:42:40Z")

</div>

IIRC aggs\_execute was the name for aggregation "value scripts". These are aggs scripts which are run on each value of an aggregation, instead of each document. Doc values (the `doc` variable) are not available. Instead, `_value` provides the current value being aggregated on, and the final value is returned by the script.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 17, 2019, 11:42pm UTC](https://discuss.elastic.co/t/allowed-script-contexts-list/195549/5 "2019-09-17T23:42:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
