# Custom Authorization Engine issue

**URL:** <https://discuss.elastic.co/t/custom-authorization-engine-issue/305024>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 18, 2022, 6:46am UTC](https://discuss.elastic.co/t/custom-authorization-engine-issue/305024 "2022-05-18T06:46:32Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![ash\_n](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ash_n/32/105820_2.png) [@ash\_n](https://discuss.elastic.co/u/ash_n)\
**Post date:** [May 18, 2022, 6:46am UTC](https://discuss.elastic.co/t/custom-authorization-engine-issue/305024/1 "2022-05-18T06:46:32Z")

</div>

I'm working on an implementation of a custom authorization engine by following the instructions on [this](https://www.elastic.co/guide/en/elasticsearch/reference/current/custom-roles-authorization.html#implementing-authorization-engine) page and using [this](https://github.com/elastic/elasticsearch/tree/v8.2.0/plugins/examples/security-authorization-engine) sample. I'm using Elasticsearch v8.2.0.

I've been able to generate the single zip file for my custom authorization engine and I've followed the steps to use the security extension as described on that page. I implemented the [AuthorizationEngine](https://github.com/elastic/elasticsearch/blob/v8.2.0/x-pack/plugin/core/src/main/java/org/elasticsearch/xpack/core/security/authz/AuthorizationEngine.java) to basically deny index operations. So implemented [this](https://github.com/elastic/elasticsearch/blob/v8.2.0/x-pack/plugin/core/src/main/java/org/elasticsearch/xpack/core/security/authz/AuthorizationEngine.java#L134) method to deny.

The issue I'm facing is I don't think the security extension is being called as all my index actions like create, delete are succeeding. I would have expected a denial while running index-related actions. Even the logs don't seem to provide any information about whether the extension is used or not. Although the logs do say that my plugin was loaded. Any idea if I'm missing something ?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 18, 2022, 10:53am UTC](https://discuss.elastic.co/t/custom-authorization-engine-issue/305024/2 "2022-05-18T10:53:56Z")

</div>

Authorization Engines are pretty tricky to get right, and are a really advanced feature. Are you sure that's the right answer to the problem you have?

I definitely do not recommend it if you have any other options.

It's hard to debug the problem without seeing your code. The only advice I can offer is to take it 1 step at a time. Put some logging in the constructor for your `SecurityExtension` and then some in the `getAuthorizationEngine` method and see whether they're being called.

---

<div class="post-metadata">

**Author:** ![ash\_n](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ash_n/32/105820_2.png) [@ash\_n](https://discuss.elastic.co/u/ash_n)\
**Post date:** [May 18, 2022, 5:18pm UTC](https://discuss.elastic.co/t/custom-authorization-engine-issue/305024/3 "2022-05-18T17:18:54Z")

</div>

I'm trying to use an external authorization engine to authorize requests that ES gets. [Here](https://github.com/ashutosh-narkar/elasticsearch-opa) is the code.

I was using print statements to figure out if the code is being called but I'll try to add some logs. Please do let me know if the code looks ok. I appreciate the help.

Thanks

---

<div class="post-metadata">

**Author:** ![ash\_n](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ash_n/32/105820_2.png) [@ash\_n](https://discuss.elastic.co/u/ash_n)\
**Post date:** [May 18, 2022, 7:04pm UTC](https://discuss.elastic.co/t/custom-authorization-engine-issue/305024/4 "2022-05-18T19:04:09Z")

</div>

I added some logging as you suggested. I can see [this](https://github.com/ashutosh-narkar/elasticsearch-opa/blob/main/src/main/java/com/elasticsearch/opa/OpaAuthorizationEngineExtension.java#L17) and [this](https://github.com/ashutosh-narkar/elasticsearch-opa/blob/main/src/main/java/com/elasticsearch/opa/OpaAuthorizationEngine.java#L43) log in the ES logs.

But when I run a query I would have expected to see [this](https://github.com/ashutosh-narkar/elasticsearch-opa/blob/main/src/main/java/com/elasticsearch/opa/OpaAuthorizationEngine.java#L85) log for example but I don't.

Also if it helps this is how I run a query:

```auto
$ curl -k -u elastic:zymvKQ2vtKba5uPOiXAW -X POST "https://localhost:9200/logs-my_app-default/_doc?pretty" -H 'Content-Type: application/json' -d'
{
  "@timestamp": "2099-05-06T16:21:15.000Z",
  "event": {
    "original": "192.0.2.42 - - [06/May/2099:16:21:15 +0000] \"GET /images/bg.jpg HTTP/1.0\" 200 24736"
  }
}'

```

```auto
$ curl -k -u elastic:zymvKQ2vtKba5uPOiXAW -X DELETE "https://localhost:9200/_data_stream/logs-my_app-default?pretty"

```

```auto
$ curl --cacert http_ca.crt -u elastic -X POST "https://localhost:9200/logs-my_app-default/_doc?pretty" -H 'Content-Type: application/json' -d'
{
  "@timestamp": "2099-05-06T16:21:15.000Z",
  "event": {
    "original": "192.0.2.42 - - [06/May/2099:16:21:15 +0000] \"GET /images/bg.jpg HTTP/1.0\" 200 24736"
  }
}'

```

```auto
$ curl --cacert http_ca.crt -u elastic -X DELETE "https://localhost:9200/_data_stream/logs-my_app-default?pretty"

```

Do you expect the above queries to hit some of the methods of the AuthorizationEngine interface ?

---

<div class="post-metadata">

**Author:** ![ash\_n](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ash_n/32/105820_2.png) [@ash\_n](https://discuss.elastic.co/u/ash_n)\
**Post date:** [May 19, 2022, 5:56pm UTC](https://discuss.elastic.co/t/custom-authorization-engine-issue/305024/5 "2022-05-19T17:56:36Z")

</div>

@TimV if you need any more information please do let me know. I appreciate your feedback. Thanks!

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 20, 2022, 4:39am UTC](https://discuss.elastic.co/t/custom-authorization-engine-issue/305024/6 "2022-05-20T04:39:45Z")

</div>

The problem is that you are testing with the `elastic` user. Builtin users will always use the RBAC engine. You need to use a custom user if you want to use your own engine.

---

<div class="post-metadata">

**Author:** ![ash\_n](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ash_n/32/105820_2.png) [@ash\_n](https://discuss.elastic.co/u/ash_n)\
**Post date:** [May 20, 2022, 4:54am UTC](https://discuss.elastic.co/t/custom-authorization-engine-issue/305024/7 "2022-05-20T04:54:42Z")

</div>

Hey @TimV thanks for your reply. I create a custom role as described [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/defining-roles.html#roles-management-file) and a custom user as described [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/users-command.html). In this case too, it looks like it uses the RBAC engine. Is this the correct way to test or can you please recommend something else ?

Secondly, I'm using `docker.elastic.co/elasticsearch/elasticsearch:8.2.0` for my setup which should fine, correct ?

---

<div class="post-metadata">

**Author:** ![ash\_n](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ash_n/32/105820_2.png) [@ash\_n](https://discuss.elastic.co/u/ash_n)\
**Post date:** [May 20, 2022, 5:17am UTC](https://discuss.elastic.co/t/custom-authorization-engine-issue/305024/8 "2022-05-20T05:17:22Z")

</div>

This is my test flow:

1. Create a custom role

```auto
$ curl --cacert http_ca.crt -u elastic -X POST "https://localhost:9200/_security/role/not_superuser?pretty" -H 'Content-Type: application/json' -d'
{
  "cluster": ["monitor"],
  "indices": [
    {
      "names": ["*"],
      "privileges": ["read"]
    }
  ]
}'

```

1. Add a new user

```auto
$ docker exec -ti elasticsearch-opa_elasticsearch_1 /usr/share/elasticsearch/bin/elasticsearch-users useradd bob -p theshining -r not_superuser

```

1. Test Query 1: Create index

```auto
$ curl --cacert http_ca.crt -u bob -X PUT "https://localhost:9200/my-index-000001?pretty"
Enter host password for user 'bob':
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "action [indices:admin/create] is unauthorized for user [bob] with roles [not_superuser], this action is granted by the index privileges [create_index,manage,all]"
      }
    ],
    "type" : "security_exception",
    "reason" : "action [indices:admin/create] is unauthorized for user [bob] with roles [not_superuser], this action is granted by the index privileges [create_index,manage,all]"
  },
  "status" : 403
}

```

1. Test Query 2: Add a single document

```auto
$ curl --cacert http_ca.crt -u bob -X POST "https://localhost:9200/logs-my_app-default/_doc?pretty" -H 'Content-Type: application/json' -d'
{
  "@timestamp": "2099-05-06T16:21:15.000Z",
  "event": {
    "original": "192.0.2.42 - - [06/May/2099:16:21:15 +0000] \"GET /images/bg.jpg HTTP/1.0\" 200 24736"
  }
}
'
Enter host password for user 'bob':
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "action [indices:data/write/index] is unauthorized for user [bob] with roles [not_superuser], this action is granted by the index privileges [create_doc,create,index,write,all]"
      }
    ],
    "type" : "security_exception",
    "reason" : "action [indices:data/write/index] is unauthorized for user [bob] with roles [not_superuser], this action is granted by the index privileges [create_doc,create,index,write,all]"
  },
  "status" : 403
}

```

In both the test cases, the RBAC engine seems to be making the decision and not the custom engine.

---

<div class="post-metadata">

**Author:** ![ash\_n](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ash_n/32/105820_2.png) [@ash\_n](https://discuss.elastic.co/u/ash_n)\
**Post date:** [May 20, 2022, 7:25pm UTC](https://discuss.elastic.co/t/custom-authorization-engine-issue/305024/9 "2022-05-20T19:25:49Z")

</div>

When I start ES with `xpack.license.self_generated.type=trial`, now my custom authorization code is now being called. Thanks @TimV , appreciate the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 17, 2022, 7:26pm UTC](https://discuss.elastic.co/t/custom-authorization-engine-issue/305024/10 "2022-06-17T19:26:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
