# App Search Roles

**URL:** <https://discuss.elastic.co/t/app-search-roles/318704>\
**Category:** Elastic Search\
**Tags:** elastic-app-search\
**Created:** [November 11, 2022, 5:10am UTC](https://discuss.elastic.co/t/app-search-roles/318704 "2022-11-11T05:10:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![moassafiri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moassafiri/32/110323_2.png) [@moassafiri](https://discuss.elastic.co/u/moassafiri)\
**Post date:** [November 11, 2022, 5:10am UTC](https://discuss.elastic.co/t/app-search-roles/318704/1 "2022-11-11T05:10:05Z")

</div>

Hi Team,

Is it possible to create custom App Search roles? We're looking to give a user Read-Only access to all the elements that a Developer can see (Crawlers, Curations etc) - but not give them write access.

Thanks,

---

<div class="post-metadata">

**Author:** ![moassafiri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moassafiri/32/110323_2.png) [@moassafiri](https://discuss.elastic.co/u/moassafiri)\
**Post date:** [November 22, 2022, 5:57am UTC](https://discuss.elastic.co/t/app-search-roles/318704/2 "2022-11-22T05:57:26Z")

</div>

So looked into using a Pipeline with a custom role to solve this particular problem - without any luck.

The pipeline works when using the simulator, but when attempting to do it via the App Search GUI, it appears the pipeline just doesn't set the `set_security_user` correctly.

The pipeline definitely runs because if there is no condition on the `fail` process - the pipeline works as expected and blocks out any changes - however it needs to be conditional based on the user executing the change.

Is there a way to log the `ctx` object anywhere when it's run through the AppSearch pipeline?

```auto
[
  {
    "set_security_user": {
      "field": "_security",
      "properties": [
        "roles"
      ]
    }
  },
  {
    "fail": {
      "message": "Cannot Run",
      "if": "ctx._security.roles.contains(\"developer-tester\")"
    }
  },
  {
    "remove": {
      "field": "_security"
    }
  }
]

```

Failure proceedure:

```auto
[
  {
    "remove": {
      "field": "_security"
    }
  },
  {
    "script": {
      "source": "ctx.op = \"noop\";"
    }
  }
]

```

---

<div class="post-metadata">

**Author:** ![moassafiri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moassafiri/32/110323_2.png) [@moassafiri](https://discuss.elastic.co/u/moassafiri)\
**Post date:** [November 22, 2022, 10:45pm UTC](https://discuss.elastic.co/t/app-search-roles/318704/3 "2022-11-22T22:45:55Z")

</div>

I wrote the CTX back to the Document and I'm getting this regardless of the user that's logged into Kibana via the GUI.

Is there anyway to get the authenticated user from the `Set Security User` process instead of just the Kibana System information?

```
          "roles": [
            "kibana_system",
            "cloud-internal-enterprise_search-server"
          ],
          "realm": {
            "name": "found",
            "type": "file"
          },
          "authentication_type": "REALM",
          "username": "cloud-internal-enterprise_search-server"
        }

```

---

<div class="post-metadata">

**Author:** ![moassafiri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moassafiri/32/110323_2.png) [@moassafiri](https://discuss.elastic.co/u/moassafiri)\
**Post date:** [November 23, 2022, 4:37am UTC](https://discuss.elastic.co/t/app-search-roles/318704/4 "2022-11-23T04:37:36Z")

</div>

Raised an Issue:

> <https://github.com/elastic/kibana/issues/146091>
>
> \*\*Kibana version:\*\*
> 8.4.3
> 
> \*\*Elasticsearch version:\*\*
> 8.4.3
> 
> \*\*Server OS v…ersion:\*\*
> Cloud
> 
> \*\*Browser version:\*\*
> Chrome
> 
> \*\*Browser OS version:\*\*
> 107
> 
> \*\*Original install method (e.g. download page, yum, from source, etc.):\*\*
> Cloud
> 
> \*\*Describe the bug:\*\*
> Elastic Search Ingest Pipelines \`Set Security User\` is being obscured by Kibana user, when should be returning the end user making the changes. This is critical to pass user information to Painless for additional logic / logging.
> 
> \*\*Steps to reproduce:\*\*
> 1. Create an Ingest Pipeline with \`Set Security User\` and add it to Default pipeline on an Enterprise Search Index (eg: \`.ent-search-actastic-engines\_v26\`). Set Security User to a field like \`ctx.\_security\`.
> 3. Make a change to Enterprise Search via Kibana
> 4. Open the document and find the \`document\['\_security'\]\` that was written from the Ingest Pipeline. 
> \`\`\`
> {
> "roles": \[
> "kibana\_system",
> "cloud-internal-enterprise\_search-server"
> \],
> "realm": {
> "name": "found",
> "type": "file"
> },
> "authentication\_type": "REALM",
> "username": "cloud-internal-enterprise\_search-server"
> }
> \`\`\`      
> 
> \*\*Expected behavior:\*\*
> Expected Behavior is having the End User as the Security User being sent through the Ingest Pipeline, not the default Kibana username/roles.
> 
> When using the Ingest Pipeline simulator directly on ElasticSearch, this is the response which is the correct response:
> 
> \`\`\`
> "\_security": {
> "metadata": {
> "saml\_email": \[
> "redacted"
> \],
> "saml\_nameid\_format": "urn:oasis:names:tc:SAML:2.0:nameid-format:transient",
> "saml(http://saml.elastic-cloud.com/attributes/principal)": \[
> "redacted"
> \],
> "saml\_roles": \[
> "superuser"
> \],
> "saml\_principal": \[
> "redacted"
> \],
> "saml\_nameid": "redacted",
> "saml(http://saml.elastic-cloud.com/attributes/name)": \[
> "redacted"
> \],
> "saml(http://saml.elastic-cloud.com/attributes/email)": \[
> "redacted"
> \],
> "saml(http://saml.elastic-cloud.com/attributes/roles)": \[
> "superuser"
> \],
> "saml\_name": \[
> "redacted"
> \]
> },
> "full\_name": "redacted",
> "roles": \[
> "superuser"
> \],
> "realm": {
> "name": "cloud-saml-kibana",
> "type": "saml"
> },
> "authentication\_type": "TOKEN",
> "email": "redacted",
> "username": "redacted"
> 
> 
> \`\`\`
> \*\*Screenshots (if relevant):\*\*
> The \`ctx\` when doing an action via Kibana
> https://imgur.com/a/umI4Jn1
> 
> When simulating via the Pipeline:
> https://imgur.com/a/UtlOYJI
> 
> \*\*Errors in browser console (if relevant):\*\*
> None
> 
> \*\*Provide logs and/or server output (if relevant):\*\*
> 
> \*\*Any additional context:\*\*

This seems like a bug to me.

Kibana should be passing through the actual user making the change on the Enterprise Search engines - not the Kibana\_system user.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 21, 2022, 4:37am UTC](https://discuss.elastic.co/t/app-search-roles/318704/5 "2022-12-21T04:37:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
