# Feature request? Ignore allow\_explicit\_index when accessing root /\_bulk URL

**URL:** <https://discuss.elastic.co/t/feature-request-ignore-allow-explicit-index-when-accessing-root--bulk-url/19252>\
**Category:** Elasticsearch\
**Created:** [August 13, 2014, 12:37pm UTC](https://discuss.elastic.co/t/feature-request-ignore-allow-explicit-index-when-accessing-root--bulk-url/19252 "2014-08-13T12:37:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![11163](https://avatars.discourse-cdn.com/v4/letter/1/258eb7/32.png) [@11163](https://discuss.elastic.co/u/11163)\
**Post date:** [August 13, 2014, 12:37pm UTC](https://discuss.elastic.co/t/feature-request-ignore-allow-explicit-index-when-accessing-root--bulk-url/19252/1 "2014-08-13T12:37:20Z")

</div>

Hello,

When url-based access control is used for bulk requests

rest.action.multi.allow\_explicit\_index: false

[http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/url-access-control.html](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/url-access-control.html)  
It forbids explicitly setting the index in the request body regardless of  
the bulk url used.

Would it be possible to allow setting explicit indexes when the URL  
accessed is the /\_bulk root, with no index specified in the URL?

This way if a user is allowed to access /\_bulk, he can work as if  
allow\_explicit\_index is false, while if a user is only allowed to access  
specific {index}/\_bulk urls, he is effectively contained.

With the current rules, the only way to allow bulk access with explicit  
index to one user is to set allow\_explicit\_index to true and thus allow  
full access to everybody with bulk access.

Maybe this feature is not that high-priority, I see that access control in  
general does not seem to be the focus of elasticsearch. But if this is an  
easy change, would this work?

Thanks,  
Ivan

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/58bee79e-2e30-4dc2-809b-d2b6ba275336%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/58bee79e-2e30-4dc2-809b-d2b6ba275336%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 13, 2014, 12:46pm UTC](https://discuss.elastic.co/t/feature-request-ignore-allow-explicit-index-when-accessing-root--bulk-url/19252/2 "2014-08-13T12:46:26Z")

</div>

That'd be worth entering in here -  
[Issues · elastic/elasticsearch · GitHub](https://github.com/elasticsearch/elasticsearch/issues) 🙂

Regards,  
Mark Walkom

Infrastructure Engineer  
Campaign Monitor  
email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
web: [www.campaignmonitor.com](http://www.campaignmonitor.com)

On 13 August 2014 22:37, Иван Кадочников [fizmat.r66@gmail.com](mailto:fizmat.r66@gmail.com) wrote:

> Hello,
> 
> When url-based access control is used for bulk requests
> 
> rest.action.multi.allow\_explicit\_index: false
> 
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/url-access-control.html)  
> It forbids explicitly setting the index in the request body regardless of  
> the bulk url used.
> 
> Would it be possible to allow setting explicit indexes when the URL  
> accessed is the /\_bulk root, with no index specified in the URL?
> 
> This way if a user is allowed to access /\_bulk, he can work as if  
> allow\_explicit\_index is false, while if a user is only allowed to access  
> specific {index}/\_bulk urls, he is effectively contained.
> 
> With the current rules, the only way to allow bulk access with explicit  
> index to one user is to set allow\_explicit\_index to true and thus allow  
> full access to everybody with bulk access.
> 
> Maybe this feature is not that high-priority, I see that access control in  
> general does not seem to be the focus of elasticsearch. But if this is an  
> easy change, would this work?
> 
> Thanks,  
> Ivan
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/58bee79e-2e30-4dc2-809b-d2b6ba275336%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/58bee79e-2e30-4dc2-809b-d2b6ba275336%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/58bee79e-2e30-4dc2-809b-d2b6ba275336%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/58bee79e-2e30-4dc2-809b-d2b6ba275336%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEM624b7pArFMuT1jn%3DF\_WAc1weVNpaVYJ3CCk1r5baGZnMrWw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624b7pArFMuT1jn%3DF_WAc1weVNpaVYJ3CCk1r5baGZnMrWw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![11163](https://avatars.discourse-cdn.com/v4/letter/1/258eb7/32.png) [@11163](https://discuss.elastic.co/u/11163)\
**Post date:** [August 13, 2014, 12:50pm UTC](https://discuss.elastic.co/t/feature-request-ignore-allow-explicit-index-when-accessing-root--bulk-url/19252/3 "2014-08-13T12:50:34Z")

</div>

Ok, done.  
I was not sure if I should go right to github or ask here first =)

On 08/13/2014 04:46 PM, Mark Walkom wrote:

> That'd be worth entering in here -  
> [Issues · elastic/elasticsearch · GitHub](https://github.com/elasticsearch/elasticsearch/issues) 🙂
> 
> Regards,  
> Mark Walkom
> 
> Infrastructure Engineer  
> Campaign Monitor  
> email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com) [mailto:markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
> web: [www.campaignmonitor.com](http://www.campaignmonitor.com) [http://www.campaignmonitor.com](http://www.campaignmonitor.com)
> 
> On 13 August 2014 22:37, Иван Кадочников \<[fizmat.r66@gmail.com](mailto:fizmat.r66@gmail.com)  
> [mailto:fizmat.r66@gmail.com](mailto:fizmat.r66@gmail.com)\> wrote:
> 
> ```
> Hello,
> 
> When url-based access control is used for bulk requests
> 
> rest.action.multi.allow_explicit_index: false
> 
> http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/url-access-control.html
> It forbids explicitly setting the index in the request body
> regardless of the bulk url used.
> 
> Would it be possible to allow setting explicit indexes when the
> URL accessed is the /_bulk root, with no index specified in the URL?
> 
> This way if a user is allowed to access /_bulk, he can work as if
> allow_explicit_index is false, while if a user is only allowed to
> access specific {index}/_bulk urls, he is effectively contained.
> 
> With the current rules, the only way to allow bulk access with
> explicit index to one user is to set allow_explicit_index to true
> and thus allow full access to everybody with bulk access.
> 
> Maybe this feature is not that high-priority, I see that access
> control in general does not seem to be the focus of elasticsearch.
> But if this is an easy change, would this work?
> 
> Thanks,
> Ivan
> -- 
> You received this message because you are subscribed to the Google
> Groups "elasticsearch" group.
> To unsubscribe from this group and stop receiving emails from it,
> send an email to elasticsearch+unsubscribe@googlegroups.com
> <mailto:elasticsearch+unsubscribe@googlegroups.com>.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/elasticsearch/58bee79e-2e30-4dc2-809b-d2b6ba275336%40googlegroups.com
> <https://groups.google.com/d/msgid/elasticsearch/58bee79e-2e30-4dc2-809b-d2b6ba275336%40googlegroups.com?utm_medium=email&utm_source=footer>.
> For more options, visit https://groups.google.com/d/optout.
> 
> ```
> 
> --  
> You received this message because you are subscribed to a topic in the  
> Google Groups "elasticsearch" group.  
> To unsubscribe from this topic, visit  
> [https://groups.google.com/d/topic/elasticsearch/aNj84bHWfDE/unsubscribe](https://groups.google.com/d/topic/elasticsearch/aNj84bHWfDE/unsubscribe).  
> To unsubscribe from this group and all its topics, send an email to  
> [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com)  
> [mailto:elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/CAEM624b7pArFMuT1jn%3DF\_WAc1weVNpaVYJ3CCk1r5baGZnMrWw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624b7pArFMuT1jn%3DF_WAc1weVNpaVYJ3CCk1r5baGZnMrWw%40mail.gmail.com)  
> [https://groups.google.com/d/msgid/elasticsearch/CAEM624b7pArFMuT1jn%3DF\_WAc1weVNpaVYJ3CCk1r5baGZnMrWw%40mail.gmail.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/CAEM624b7pArFMuT1jn%3DF_WAc1weVNpaVYJ3CCk1r5baGZnMrWw%40mail.gmail.com?utm_medium=email&utm_source=footer).  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/53EB5F1A.3000803%40gmail.com](https://groups.google.com/d/msgid/elasticsearch/53EB5F1A.3000803%40gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:08am UTC](https://discuss.elastic.co/t/feature-request-ignore-allow-explicit-index-when-accessing-root--bulk-url/19252/4 "2017-07-06T01:08:54Z")

</div>


