# Document level security: placeholders for USERNAME and ROLE in the role's query

**URL:** <https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953>\
**Category:** Elasticsearch\
**Created:** [January 18, 2017, 8:41am UTC](https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953 "2017-01-18T08:41:13Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [January 18, 2017, 8:41am UTC](https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953/1 "2017-01-18T08:41:13Z")

</div>

Hello All,

I'm wondering if it is possible to use placeholders (like  
{USERNAME} or {ROLENAME} in the `"Edit Role"` query for restricting access to some documents?  
Let's say, we'd have the following ACL field in a document:

```
"acl_allow": ["user1", "group1", "group2"]

```

Then the following **general** `Indices Privileges` query would grant access to `user1` only:

```
{"match": {"acl_allow": "{USERNAME}" } }

```

The same method could be used to restrict access by groups/roles. As you can imagine, the point is: to reduce the role management efforts on the Elasticsearch side, because the mapping feature (`unmapped_groups_as_roles: true`) of external realms would allow us to manage access externally (in AD/LDAP).

Make sense? 🙂  
Thank you!

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 18, 2017, 11:25am UTC](https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953/2 "2017-01-18T11:25:39Z")

</div>

> [@jetnet](#):
>
> I'm wondering if it is possible to use placeholders (like {USERNAME} or {ROLENAME} in the "Edit Role" query for restricting access to some documents?

Assuming I understand your question correctly, the feature you are looking for is [templates in role queries](https://www.elastic.co/guide/en/x-pack/current/field-and-document-access-control.html#templating-role-query).

---

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [January 18, 2017, 1:44pm UTC](https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953/3 "2017-01-18T13:44:01Z")

</div>

That is exactly, what I was looking for! Sorry, I didn't realized it has been documented already!  
So, I'm trying the template role query right now, but I'm not getting results:

```
GET /_xpack/security/role/searchgrp
{
  "searchgrp": {
	"cluster": [],
	"indices": [
	  {
		"names": [
		  "topbeat-*",
		  "test",
		  ".kibana"
		],
		"privileges": [
		  "read",
		  "view_index_metadata"
		],
		"field_security": {
		  "grant": [
			"*"
		  ]
		},
		"query": "{ \"match\" : { \"acl_allow\" : \"{{_user.username}}\" }}"
	  }
	],
	"run_as": [],
	"metadata": {}
  }
}

```

Query:

```
GET http://localhost:9200/test/_search
{
	"took": 2,
	"timed_out": false,
	"_shards": {
		"total": 1,
		"successful": 1,
		"failed": 0
	},
	"hits": {
		"total": 0,
		"max_score": null,
		"hits": []
	}
}

```

Logs:

```
[2017-01-18T14:27:26,784][DEBUG][o.e.x.s.a.a.ActiveDirectoryRealm] [host] authenticated user [search], with roles [[searchgrp, Domain Users, Users]]
[2017-01-18T14:27:26,790] [transport] [access_granted] origin_type=[rest], origin_address=[127.0.0.1], principal=[search], action=[indices:data/read/search], indices=[test], request=[SearchRequest]
[2017-01-18T14:27:26,791] [transport] [access_granted] origin_type=[rest], origin_address=[127.0.0.1], principal=[search], action=[indices:data/read/search[phase/query+fetch]], indices=[test], request=[ShardSearchTransportRequest]

```

If I replace the template `{{_user.username}}` by the real user name ("search") in the role query, then the "secured" documents get found.

Am I missing something?

Thank you!

**Update** :  
Index mapping:

```
PUT test
{
  "mappings": {
	"t": {
	  "properties": {
		"acl_allow": {
		  "type": "string",
		  "index": "not_analyzed"
		}
	  }
	}
  }
}

```

corresponding superuser query:

```
GET test/_search
{
  "query": {
	"match": {
	  "acl_allow": "search"
	}
  }
}

{
  "took": 1,
  "timed_out": false,
  "_shards": {
	"total": 1,
	"successful": 1,
	"failed": 0
  },
  "hits": {
	"total": 1,
	"max_score": 1.2039728,
	"hits": [
	  {
		"_index": "test",
		"_type": "t",
		"_id": "1",
		"_score": 1.2039728,
		"_source": {
		  "title": "document 1",
		  "acl_allow": [
			"search"
		  ]
		}
	  }
	]
  }
}

```

**Update II**  
Upgraded the ES instance from 5.0.0 to 5.1.2 - no improvements, can't make the "mustache" template working.  
Any suggestions would be highly appreciated!  
Thanks!

---

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [January 22, 2017, 12:13am UTC](https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953/4 "2017-01-22T00:13:29Z")

</div>

so, is it a bug?..

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [January 23, 2017, 5:17pm UTC](https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953/5 "2017-01-23T17:17:14Z")

</div>

You need to use the `template` query in the role for the substitutions to work

---

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [January 23, 2017, 5:36pm UTC](https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953/6 "2017-01-23T17:36:32Z")

</div>

I apologize! Indeed, I forgot to "template" the role query!  
Sorry again - everything is well documented and working!

Thank you very much guys!

---

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [January 23, 2017, 7:07pm UTC](https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953/7 "2017-01-23T19:07:56Z")

</div>

I'm sorry, still need help with `_user.roles` template. Since it should contain a list of the role names of the current user, I assume, that the `terms` query should be used. The following role query does not produce result:

```
{
  "template": {
	"inline": {
		  "terms": {"acl_allow":["{{_user.roles}}"]}
		}
  }
}

```

What is the right way to query with `_user.roles` list?  
Thank you!

---

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [January 23, 2017, 9:23pm UTC](https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953/8 "2017-01-23T21:23:18Z")

</div>

I did my "homework", and it turned out, that this topic is a duplicate of [X-Pack Security : Role definition query template with 'terms'](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790)

Anyway, I'm going to summarize my "finding" here again:

**User** :

```
{
	"template": {
		"inline": {
			"match": {
				"acl_allow": "{{_user.username}}"
			}
		}
	}
}

```

**Roles** :

```
{
	"template": {
		"inline": "{\"terms\":{\"acl_allow\": {{#toJson}}_user.roles{{/toJson}}}}"
	}
}

```

Thank you for your help again!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2017, 9:23pm UTC](https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953/9 "2017-02-20T21:23:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
