# Disable dynamic scripting in Elasticsearch Grails Plugin

**URL:** <https://discuss.elastic.co/t/disable-dynamic-scripting-in-elasticsearch-grails-plugin/52900>\
**Category:** Elasticsearch\
**Created:** [June 15, 2016, 5:23pm UTC](https://discuss.elastic.co/t/disable-dynamic-scripting-in-elasticsearch-grails-plugin/52900 "2016-06-15T17:23:37Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mdhavale](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@mdhavale](https://discuss.elastic.co/u/mdhavale)\
**Post date:** [June 15, 2016, 5:23pm UTC](https://discuss.elastic.co/t/disable-dynamic-scripting-in-elasticsearch-grails-plugin/52900/1 "2016-06-15T17:23:37Z")

</div>

This is kind of a longshot, but does anyone know a means of disabling dynamic scripting in the Elasticsearch grails plugin? The plugin doesn't have all the features/toggles of normal ES. I'm just curious if anyone has encountered this before. I realize ES grails plugin != ES.

Thank you in advance.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 16, 2016, 7:50am UTC](https://discuss.elastic.co/t/disable-dynamic-scripting-in-elasticsearch-grails-plugin/52900/2 "2016-06-16T07:50:03Z")

</div>

Hi

just had a quick peek at the source... so no guarantees 🙂

If you use the transport client, then there is no need to configure scripting, as you are on the server side. See [https://github.com/noamt/elasticsearch-grails-plugin/blob/master/src/main/groovy/grails/plugins/elasticsearch/ClientNodeFactoryBean.groovy#L68-L92](https://github.com/noamt/elasticsearch-grails-plugin/blob/master/src/main/groovy/grails/plugins/elasticsearch/ClientNodeFactoryBean.groovy#L68-L92)

If you use the `local` mode, you could supply your own config file, but I htink for a web app, the `TransportClient` makes the most sense.

--Alex

---

<div class="post-metadata">

**Author:** ![mdhavale](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@mdhavale](https://discuss.elastic.co/u/mdhavale)\
**Post date:** [June 16, 2016, 1:17pm UTC](https://discuss.elastic.co/t/disable-dynamic-scripting-in-elasticsearch-grails-plugin/52900/3 "2016-06-16T13:17:11Z")

</div>

Hi Alexander,

Thanks so much for your response. I should have specified, the reason I'm asking is because the version of ES that's embedded in the plugin is old and has a scripting vulnerability. Disabling dynamic scripting is a way of remediating that vulnerability.

In the meantime, I had a look at the source as well; I was examining it to see if it actually supported any of the parameters I was interested in, specifically:

- elasticsearch.script.disable\_dynamic
- elasticsearch.script.groovy.sandbox.enabled  
I couldn't find instances of either of those in the code (although I found other things, like disableDynamicMethodsInjection). So, my thought is no, those features were not implemented in the grails plugin.

Thanks again for your response!!!

Mike

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 16, 2016, 3:04pm UTC](https://discuss.elastic.co/t/disable-dynamic-scripting-in-elasticsearch-grails-plugin/52900/4 "2016-06-16T15:04:41Z")

</div>

Hey,

the plugin still seems to use 1.x, where you should use 2.x... So IMO either update the plugin (and then use a `TransportClient` and you dont have to worry about this) or run your own.

In 5.0 we will hopefully have a HTTP based client, so you are independent from the Elasticsearch version being used on the server side.

--Alex

---

<div class="post-metadata">

**Author:** ![mdhavale](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@mdhavale](https://discuss.elastic.co/u/mdhavale)\
**Post date:** [June 17, 2016, 9:01pm UTC](https://discuss.elastic.co/t/disable-dynamic-scripting-in-elasticsearch-grails-plugin/52900/5 "2016-06-17T21:01:10Z")

</div>

Hi Alex,

Thank you! Yup, I think that's my only option at this point. Thanks again for your help!

Mike

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:42pm UTC](https://discuss.elastic.co/t/disable-dynamic-scripting-in-elasticsearch-grails-plugin/52900/6 "2017-07-05T22:42:41Z")

</div>


