# Authorization per alias problem

**URL:** <https://discuss.elastic.co/t/authorization-per-alias-problem/83418>\
**Category:** Kibana\
**Created:** [April 24, 2017, 1:28pm UTC](https://discuss.elastic.co/t/authorization-per-alias-problem/83418 "2017-04-24T13:28:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jhn134910](https://avatars.discourse-cdn.com/v4/letter/j/90ced4/32.png) [@jhn134910](https://discuss.elastic.co/u/jhn134910)\
**Post date:** [April 24, 2017, 1:28pm UTC](https://discuss.elastic.co/t/authorization-per-alias-problem/83418/1 "2017-04-24T13:28:30Z")

</div>

Hello there,  
I'm using elastic-search, kibana and x-pack version 5.1.2, I'm using the native user-store.  
I have two different aliases and templates:

```auto
$ cat irldf-campaign_manager_stats_template.json
{
    "aliases": {
        "irldf-campaign_stats": {}
    },
    "mappings": {
        "campaign_stats": {
            "properties": {
...
        }
    },
    "template": "irldf-campaign_manager_stats-*"
}

```

```auto
$ cat irlh3-campaign_manager_stats_template.json
{
    "aliases": {
        "irlh3-campaign_stats": {}
    },
    "mappings": {
        "campaign_stats": {
            "properties": {
...            
        }
    },
    "template": "irlh3-campaign_manager_stats-*"
}

```

```auto
$ !1079
curl -XGET -u elastic 'localhost:9200/_cat/aliases?pretty';
Enter host password for user 'elastic':
irlh3-campaign_stats irlh3-campaign_manager_stats-test - - -
irldf-campaign_stats irldf-campaign_manager_stats-test - - -

```

Then I've configured two roles associated with both aliases and assigned them to users:

```auto
$ curl -XGET 'localhost:9200/_xpack/security/role?pretty'
{
...
  "irlh3" : {
    "cluster" : [],
    "indices" : [
      {
        "names" : [
          "irlh3-campaign_stats"
        ],
        "privileges" : [
          "all"
        ]
      },
      {
        "names" : [
          ".kibana*"
        ],
        "privileges" : [
          "manage",
          "read",
          "index"
        ]
      },
      {
        "names" : [
          ".reporting*"
        ],
        "privileges" : [
          "manage",
          "read",
          "index"
        ]
      }
    ],
    "run_as" : [],
    "metadata" : { }
  },
  "irldf" : {
    "cluster" : [],
    "indices" : [
      {
        "names" : [
          "irldf-campaign_stats"
        ],
        "privileges" : [
          "all"
        ]
      },
      {
        "names" : [
          ".kibana*"
        ],
        "privileges" : [
          "manage",
          "read",
          "index"
        ]
      },
      {
        "names" : [
          ".reporting*"
        ],
        "privileges" : [
          "manage",
          "read",
          "index"
        ]
      }
    ],
    "run_as" : [],
    "metadata" : { }
  }
}

```

```auto
$ curl -XGET 'localhost:9200/_xpack/security/user/irldf_user?pretty';
{
  "irldf_user" : {
    "username" : "irldf_user",
    "roles" : [
      "irldf",
      "kibana_user",
      "reporting_user"
    ],
    "full_name" : "IRLDF User",
    "email" : "xrldf@anony.mous",
    "metadata" : { },
    "enabled" : true
  }
}

```

In kibana I create two visualization, one on each alias, and I put each visualization in separate dashboards. However, if I log into kibana with say the irldf\_user I can still see the data from both visualizations in both dashboards. That is, the authorization is not working as I expected? Did I make a mistake settings this up? I'm implementing a separate index per user model.

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [April 24, 2017, 11:12pm UTC](https://discuss.elastic.co/t/authorization-per-alias-problem/83418/2 "2017-04-24T23:12:02Z")

</div>

Looks right to me, are you sure that the data you're seeing is from the other index? How are you checking that?

---

<div class="post-metadata">

**Author:** ![jhn134910](https://avatars.discourse-cdn.com/v4/letter/j/90ced4/32.png) [@jhn134910](https://discuss.elastic.co/u/jhn134910)\
**Post date:** [April 25, 2017, 8:29am UTC](https://discuss.elastic.co/t/authorization-per-alias-problem/83418/3 "2017-04-25T08:29:31Z")

</div>

Hello Spencer,  
Thanks for your reply.  
I log into kibana as user, `irldf_user`. Then I can navigate to the dashboard `irlh3_System_Dashboard`, which I was expecting to be accessible. The `irlh3_System_Dashboard` contains one visualization `irlh3_Offers` which was created against the `irlh3-campaign_stats` alias. The `irldf_user` should not be able to access the `irlh3-campaign_stats` data. However, it seems to and returns content, so the `irldf_user` accesses data he is not supposed to have access to.

One thing that might be unusual here from above is that the mapping type is `campaign_stats` in both templates. I changed this so it was unique for each template but I got the same result. My elasticsearch.yml security config is:

```auto
xpack.security.enabled: true
xpack.security.audit.enabled: true
xpack.security.transport.ssl.enabled: false
xpack.security.http.ssl.enabled: false
xpack.security.authc:
  realms:
    native:
      type: native
      order: 0
    tango-ims-realm:
      type: tango-ims-realm
      order: 1
      maxConnections: 5
      maxConnectionsPerHost: 5
      connectionTimeout: 5000
      socketTimeout: 5000
      imsCacheSizeName: 100
      imsCacheExpiryInMinutes: 5
      serviceUrl: "http://localhost:8225"
  anonymous:
    username: _es_anonymous_user
    roles: superuser, transport_client
    authz_exception: true

```

Is it mandatory for my alias to be configured with a filter perhaps? I didn't use the filter feature as I'm operating a per tenant/user tenant, rather than including a single index containing a tenantId accessible with alias with configured filter.

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [April 25, 2017, 3:45pm UTC](https://discuss.elastic.co/t/authorization-per-alias-problem/83418/4 "2017-04-25T15:45:57Z")

</div>

> are you sure that the data you're seeing is from the other index? How are you checking that?

I guess what I meant to say is how do you know that the data in the `irlh3_Offers` visualization is actually reading only from the `irlh3-campaign_stats` data? I just recreated this exact scenario locally and this I see the expected results:

Two users (but I only gave them the irlh3/irldf roles)

 ![](https://us1.discourse-cdn.com/elastic/original/3X/b/e/be85a108ecd52657eba78d3a4a42702b126f71aa.png)

irldf role only has access to `irldf-campaign_stats`, kibana, and reporting:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a11072c1a4a6caa47d1d68387fbba91665ef1946.png)

Same for `irlh3` role, but for `irlh3-campaign_stats`:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/d/5/d58c23184e68c64038d4ef0c758324fe1ff10f4f.png)

`irlh3-campaign_stats` index pattern:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/f/d/fde091ffb19dc549bca154cff1dce8ba557ec3eb.png)

`irlh3_Offers` visualization (based on `irdh3-campaign_stats` index pattern):

 ![](https://us1.discourse-cdn.com/elastic/original/3X/3/5/350657c8803c391091c98f7fb96268b7283d2168.png)

irlh3\_System\_Dashboard from the perspective of `irlh3_user` (last 24 hours):

 ![](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a1dbf219510991365c6f8c2ca264acd298b3dc9b.png)

irlh3\_System\_Dashbaord from the perspective of `irldf_user` (last 24 hours):

 ![](https://us1.discourse-cdn.com/elastic/original/3X/2/8/28e038c4dd9a31a898bb5839d81237e909c8e97f.png)

Because of this I assume you've mapped something incorrectly (which I did several times while trying to prepare these screenshots). Can you try to take a list of screenshots like this so I can help verify that everything lines up?

Perhaps I could recommend a different approach? If you continue to index the data for `irldf` and `irlh3` into indexes with different prefixes, and then only give them access to indices with that prefix, then you can use a single index pattern for something like `*-campaign_manager_stats-*` and elasticsearch will take care of resolving which indexes each user has access to. This way there is just an `Offers` visualization and a `System Dashboard` dashboard, and they automatically show the data relevant to each user.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 23, 2017, 4:00pm UTC](https://discuss.elastic.co/t/authorization-per-alias-problem/83418/5 "2017-05-23T16:00:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
