# callWithRequest security.hasPrivileges not available

**URL:** <https://discuss.elastic.co/t/callwithrequest-security-hasprivileges-not-available/214500>\
**Category:** Kibana\
**Created:** [January 9, 2020, 9:58pm UTC](https://discuss.elastic.co/t/callwithrequest-security-hasprivileges-not-available/214500 "2020-01-09T21:58:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![diniden](https://avatars.discourse-cdn.com/v4/letter/d/6f9a4e/32.png) [@diniden](https://discuss.elastic.co/u/diniden)\
**Post date:** [January 9, 2020, 9:58pm UTC](https://discuss.elastic.co/t/callwithrequest-security-hasprivileges-not-available/214500/1 "2020-01-09T21:58:36Z")

</div>

I am attempting to use callWithRequest to fetch elastic privilieges so I can customize my user's plugin experience based on whether or not they have access to read/write to an index within elastic.

However, I can't find a single example that explains how to use a sub-object portion of the API in conjunction with callWithRequest.

For instance, I've tried:

```
callWithRequest(req, 'security.hasPrivileges', {
          user: req.auth.credentials.username,
          body: {
            cluster: 'data',
            index: {
              names: [payload.index],
              privileges: ['write']
            }
          }
        }).then(function (response) {
          return response;
        }).catch(err => {
          return { error: err, message: 'Invalid Check for Security Privileges' };
        })
```

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [January 9, 2020, 10:28pm UTC](https://discuss.elastic.co/t/callwithrequest-security-hasprivileges-not-available/214500/2 "2020-01-09T22:28:21Z")

</div>

Try the `transport.request` method:

```auto
callWithRequest(req, 'transport.request', {
  method: 'POST',
  path: '/_security/user/_has_privileges', // see https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-has-privileges.html
  body: { ... }
});

```

I'm pretty sure the `user` doesn't need to be specified in options, as it's taken from `req.headers`

---

<div class="post-metadata">

**Author:** ![diniden](https://avatars.discourse-cdn.com/v4/letter/d/6f9a4e/32.png) [@diniden](https://discuss.elastic.co/u/diniden)\
**Post date:** [January 9, 2020, 10:36pm UTC](https://discuss.elastic.co/t/callwithrequest-security-hasprivileges-not-available/214500/3 "2020-01-09T22:36:39Z")

</div>

> [@tsullivan](#):
>
> [Has privileges API | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-has-privileges.html)

This looks like it works! Thanks! Never encountered this anywhere in the docs as a suggestion (and hours of googling).

Now I'm stuck with the 'current license is non-compliant for [security]' since I'm using the elastic / kibana docker images for development.

Know of any paths I can take to work on developing under these conditions without a license? Or is a temp license a possibility?

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [January 10, 2020, 4:52pm UTC](https://discuss.elastic.co/t/callwithrequest-security-hasprivileges-not-available/214500/4 "2020-01-10T16:52:15Z")

</div>

I don't know why, but it looks like the reference for this method only shows up under "Examples" [https://www.elastic.co/guide/en/elasticsearch/client/javascript-api/master/transport\_request\_examples.html](https://www.elastic.co/guide/en/elasticsearch/client/javascript-api/master/transport_request_examples.html)

I thought it used to also be under API Reference. I'll check if I'm mistaken.

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [January 10, 2020, 6:15pm UTC](https://discuss.elastic.co/t/callwithrequest-security-hasprivileges-not-available/214500/5 "2020-01-10T18:15:39Z")

</div>

> [@diniden](#):
>
> Now I'm stuck with the 'current license is non-compliant for [security]' since I'm using the elastic / kibana docker images for development.

I'm not sure if there is a decent solution, since that's not the recommended set up for development.

There are a lot of features of security available with a Basic license, if that helps. See [Security for Elasticsearch is now free | Elastic Blog](https://www.elastic.co/blog/security-for-elasticsearch-is-now-free)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2020, 6:15pm UTC](https://discuss.elastic.co/t/callwithrequest-security-hasprivileges-not-available/214500/6 "2020-02-07T18:15:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
