# Document level security: placeholders for USERNAME and ROLE in the role's query

**URL:** <https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953>\
**Category:** Elasticsearch\
**Created:** [January 18, 2017, 8:41am UTC](https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953 "2017-01-18T08:41:13Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [January 23, 2017, 9:23pm UTC](https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953/8 "2017-01-23T21:23:18Z")

</div>

I did my "homework", and it turned out, that this topic is a duplicate of [X-Pack Security : Role definition query template with 'terms'](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790)

Anyway, I'm going to summarize my "finding" here again:

**User** :

```
{
	"template": {
		"inline": {
			"match": {
				"acl_allow": "{{_user.username}}"
			}
		}
	}
}

```

**Roles** :

```
{
	"template": {
		"inline": "{\"terms\":{\"acl_allow\": {{#toJson}}_user.roles{{/toJson}}}}"
	}
}

```

Thank you for your help again!

---

_[View the full topic](https://discuss.elastic.co/t/document-level-security-placeholders-for-username-and-role-in-the-roles-query/71953)._
