# Basic Authentication using RestFilter

**URL:** <https://discuss.elastic.co/t/basic-authentication-using-restfilter/97051>\
**Category:** Elasticsearch\
**Created:** [August 15, 2017, 5:12am UTC](https://discuss.elastic.co/t/basic-authentication-using-restfilter/97051 "2017-08-15T05:12:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![arimoham](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@arimoham](https://discuss.elastic.co/u/arimoham)\
**Post date:** [August 15, 2017, 5:12am UTC](https://discuss.elastic.co/t/basic-authentication-using-restfilter/97051/1 "2017-08-15T05:12:07Z")

</div>

I'm trying to implement basic authentication on elasticsearch using RestFilter as given in below post's:

> [@Using RestHandlers for custom Authentication Plugin](https://discuss.elastic.co/t/using-resthandlers-for-custom-authentication-plugin/90709):
>
> Hi, I am trying to write simple custom authentication plugin for elasticsearch v5.4.1. In previous versions before 5.4.2, it could be done with Restfilters. But now they are not present. Somewhere i read that use RestHandlers for the same. However , I am not able to get code executed inside my custom handler. What i am trying to achieve is that i will get a header having authentication information in my rest request. Will validate that information using external services inside my custom handl…

and

[https://qbox.io/blog/secure-elasticsearch-authentication-plugin-tutorial](https://qbox.io/blog/secure-elasticsearch-authentication-plugin-tutorial)

Looks like from version greater than 5.1.2, RestFilter can not be registered to RestHandler, as the RestFilter class itself removed from org.elasticsearch.rest package.

Can somebody please let me know how to achieve basic authentication using RestFilter or RestHandler to add it as plugin to Elasticsearch?

According to @chanchal in post - [Using RestHandlers for custom Authentication Plugin](https://discuss.elastic.co/t/using-resthandlers-for-custom-authentication-plugin/90709), he is able to create his custom AuthenticationFilter by extending RestFilter in ES version 5.4.2 - not sure how he is able to do that when RestFilter is removed from org.elasticsearch.rest package.

Any help on his would greatly appreciated, please.

thanks

---

<div class="post-metadata">

**Author:** ![s1monw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s1monw/32/3637_2.png) [@s1monw](https://discuss.elastic.co/u/s1monw)\
**Post date:** [August 18, 2017, 10:17am UTC](https://discuss.elastic.co/t/basic-authentication-using-restfilter/97051/2 "2017-08-18T10:17:51Z")

</div>

when you plugin implements `ActionPlugin` you can override `getRestHandlerWrapper` that wrapps every rest handler before executing this should help.

---

<div class="post-metadata">

**Author:** ![arimoham](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@arimoham](https://discuss.elastic.co/u/arimoham)\
**Post date:** [August 18, 2017, 2:36pm UTC](https://discuss.elastic.co/t/basic-authentication-using-restfilter/97051/3 "2017-08-18T14:36:57Z")

</div>

Thanks for your reply @s1monw.

My main concern is - RestController api doesn't support 'registerFilter' method anymore as shown below

@Inject  
public AuthenticationHandler(Settings settings, RestController controller) {  
super(settings);  
controller.registerFilter(new AuthenticationFilter());  
}

And also, RestFilter class is also removed from elasticsearch API, so I cant extend this class and create a custom filter class as shown below,

public class AuthenticationFilter extends RestFilter {  
}

I'm trying to follow the example given in below post,

> [@Using RestHandlers for custom Authentication Plugin](https://discuss.elastic.co/t/using-resthandlers-for-custom-authentication-plugin/90709/3):
>
> Thanks for the reply. I was able to create a basic plugin for the same in the following way.. My plugin class: public class ESPlugin extends Plugin implements ActionPlugin { public List\<RestHandler\> getRestHandlers(Settings settings, RestController restController, ClusterSettings clusterSettings, IndexScopedSettings indexScopedSettings, SettingsFilter settingsFilter, IndexNameExpressionResolver indexNameExpressionResolver, Supplier\<DiscoveryNodes\> nodesInCluster) { return Arrays.asList(n…

but because of above mentioned two clarifications, not sure how to proceed, please.

Could you please explain with an example or sudo code - I'm new to elasticsearch.

Many thanks in advance.

---

<div class="post-metadata">

**Author:** ![s1monw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s1monw/32/3637_2.png) [@s1monw](https://discuss.elastic.co/u/s1monw)\
**Post date:** [August 18, 2017, 2:43pm UTC](https://discuss.elastic.co/t/basic-authentication-using-restfilter/97051/4 "2017-08-18T14:43:55Z")

</div>

> [@arimoham](#):
>
> My main concern is - RestController api doesn’t support ‘registerFilter’ method anymore as shown below

true, we have a new API as I explained above you can wrap every handler and do your authentication there.

---

<div class="post-metadata">

**Author:** ![arimoham](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@arimoham](https://discuss.elastic.co/u/arimoham)\
**Post date:** [August 18, 2017, 2:55pm UTC](https://discuss.elastic.co/t/basic-authentication-using-restfilter/97051/5 "2017-08-18T14:55:10Z")

</div>

if you dont mind, can you please explain with a sudo code for basic authentication. It will really help me, please.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 15, 2017, 2:55pm UTC](https://discuss.elastic.co/t/basic-authentication-using-restfilter/97051/6 "2017-09-15T14:55:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
