# Filtering on ACL's - Do not get the expected result

**URL:** <https://discuss.elastic.co/t/filtering-on-acls-do-not-get-the-expected-result/11627>\
**Category:** Elasticsearch\
**Created:** [April 18, 2013, 9:15am UTC](https://discuss.elastic.co/t/filtering-on-acls-do-not-get-the-expected-result/11627 "2013-04-18T09:15:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Erwin\_Rijss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erwin_rijss/32/955_2.png) [@Erwin\_Rijss](https://discuss.elastic.co/u/Erwin_Rijss)\
**Post date:** [April 18, 2013, 9:15am UTC](https://discuss.elastic.co/t/filtering-on-acls-do-not-get-the-expected-result/11627/1 "2013-04-18T09:15:28Z")

</div>

These are my documents:

$ curl -XPUT '[http://localhost:9200/test/item/1](http://localhost:9200/test/item/1)' -d '{  
"title" : "item 1",  
"securitylevels" : [  
{"usergroupcontentaccess" : [1,1,100]}  
]  
}'

$ curl -XPUT '[http://localhost:9200/test/item/2](http://localhost:9200/test/item/2)' -d '{  
"title" : "item 2",  
"securitylevels" : [  
{ "usergroupcontentaccess" : [1,1,0] },  
{ "usergroupcontentaccess" : [2,1,100] }  
]  
}'

Which says:  
On item 1  
group 1 has accesstype 1 and accesslevel 100

Which means that somebody in group 1 can view the item

and

On item 2  
group 1 has accesstype 1 and accesslevel 0  
group 2 has accesstype 1 and accesslevel 100

Which means that somebody in group 1 can _not_ view the item and somebody  
in group 2 can.

Now I like to query all the items someone in group 1 is allowed to view:

$ curl -XPOST '[http://localhost:9200/test/\_search](http://localhost:9200/test/_search)' -d '{  
"query" : {  
"filtered" : {  
"query" : { "match\_all" : {} },  
"filter" : {  
"terms" : { "securitylevels.usergroupcontentaccess" : [1,1,100],  
"execution" : "and" }  
}  
}  
}  
}'

I expect only one result, e.g. item 1, but I get both.

Another approach:

$ curl -XPOST '[http://localhost:9200/test/\_search](http://localhost:9200/test/_search)' -d '{  
"query" : {  
"terms" : { "securitylevels.usergroupcontentaccess" : [1,1,100],  
"minimum\_match" : "3" }  
}  
}'

Gives me also both records.

What do I miss? I'm using ES 0.9.0RC2

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![mvg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mvg/32/98890_2.png) [@mvg](https://discuss.elastic.co/u/mvg)\
**Post date:** [April 18, 2013, 11:10am UTC](https://discuss.elastic.co/t/filtering-on-acls-do-not-get-the-expected-result/11627/2 "2013-04-18T11:10:03Z")

</div>

Hi Erwin,

You need to use the nested field type for the field 'securitylevels':

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

This allows ES to respect the inner object structure in your documents. If  
the nested type isn't used the document structure is completely flatend and  
then at search time all `usergroupcontentaccess` values are just associated  
to your root document, which results in 2 hits.

If you use the nested type, you also need to use the nested filter in your  
case:

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Martijn

On 18 April 2013 11:15, Erwin Rijss [erijss@gmail.com](mailto:erijss@gmail.com) wrote:

> These are my documents:
> 
> $ curl -XPUT '[http://localhost:9200/test/item/1](http://localhost:9200/test/item/1)' -d '{  
> "title" : "item 1",  
> "securitylevels" : [  
> {"usergroupcontentaccess" : [1,1,100]}  
> ]  
> }'
> 
> $ curl -XPUT '[http://localhost:9200/test/item/2](http://localhost:9200/test/item/2)' -d '{  
> "title" : "item 2",  
> "securitylevels" : [  
> { "usergroupcontentaccess" : [1,1,0] },  
> { "usergroupcontentaccess" : [2,1,100] }  
> ]  
> }'
> 
> Which says:  
> On item 1  
> group 1 has accesstype 1 and accesslevel 100
> 
> Which means that somebody in group 1 can view the item
> 
> and
> 
> On item 2  
> group 1 has accesstype 1 and accesslevel 0  
> group 2 has accesstype 1 and accesslevel 100
> 
> Which means that somebody in group 1 can _not_ view the item and somebody  
> in group 2 can.
> 
> Now I like to query all the items someone in group 1 is allowed to view:
> 
> $ curl -XPOST '[http://localhost:9200/test/\_search](http://localhost:9200/test/_search)' -d '{  
> "query" : {  
> "filtered" : {  
> "query" : { "match\_all" : {} },  
> "filter" : {  
> "terms" : { "securitylevels.usergroupcontentaccess" : [1,1,100],  
> "execution" : "and" }  
> }  
> }  
> }  
> }'
> 
> I expect only one result, e.g. item 1, but I get both.
> 
> Another approach:
> 
> $ curl -XPOST '[http://localhost:9200/test/\_search](http://localhost:9200/test/_search)' -d '{  
> "query" : {  
> "terms" : { "securitylevels.usergroupcontentaccess" : [1,1,100],  
> "minimum\_match" : "3" }  
> }  
> }'
> 
> Gives me also both records.
> 
> What do I miss? I'm using ES 0.9.0RC2
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Met vriendelijke groet,

Martijn van Groningen

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Erwin\_Rijss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erwin_rijss/32/955_2.png) [@Erwin\_Rijss](https://discuss.elastic.co/u/Erwin_Rijss)\
**Post date:** [April 19, 2013, 7:45am UTC](https://discuss.elastic.co/t/filtering-on-acls-do-not-get-the-expected-result/11627/3 "2013-04-19T07:45:47Z")

</div>

Thnx!

On Thursday, April 18, 2013 1:10:03 PM UTC+2, Martijn v Groningen wrote:

> Hi Erwin,
> 
> You need to use the nested field type for the field 'securitylevels':  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/mapping/nested-type/)
> 
> This allows ES to respect the inner object structure in your documents. If  
> the nested type isn't used the document structure is completely flatend and  
> then at search time all `usergroupcontentaccess` values are just associated  
> to your root document, which results in 2 hits.
> 
> If you use the nested type, you also need to use the nested filter in your  
> case:  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/nested-filter/)
> 
> Martijn
> 
> On 18 April 2013 11:15, Erwin Rijss \<[eri...@gmail.com](mailto:eri...@gmail.com) \<javascript:\>\>wrote:
> 
> > These are my documents:
> > 
> > $ curl -XPUT '[http://localhost:9200/test/item/1](http://localhost:9200/test/item/1)' -d '{  
> > "title" : "item 1",  
> > "securitylevels" : [  
> > {"usergroupcontentaccess" : [1,1,100]}  
> > ]  
> > }'
> > 
> > $ curl -XPUT '[http://localhost:9200/test/item/2](http://localhost:9200/test/item/2)' -d '{  
> > "title" : "item 2",  
> > "securitylevels" : [  
> > { "usergroupcontentaccess" : [1,1,0] },  
> > { "usergroupcontentaccess" : [2,1,100] }  
> > ]  
> > }'
> > 
> > Which says:  
> > On item 1  
> > group 1 has accesstype 1 and accesslevel 100
> > 
> > Which means that somebody in group 1 can view the item
> > 
> > and
> > 
> > On item 2  
> > group 1 has accesstype 1 and accesslevel 0  
> > group 2 has accesstype 1 and accesslevel 100
> > 
> > Which means that somebody in group 1 can _not_ view the item and  
> > somebody in group 2 can.
> > 
> > Now I like to query all the items someone in group 1 is allowed to view:
> > 
> > $ curl -XPOST '[http://localhost:9200/test/\_search](http://localhost:9200/test/_search)' -d '{  
> > "query" : {  
> > "filtered" : {  
> > "query" : { "match\_all" : {} },  
> > "filter" : {  
> > "terms" : { "securitylevels.usergroupcontentaccess" : [1,1,100],  
> > "execution" : "and" }  
> > }  
> > }  
> > }  
> > }'
> > 
> > I expect only one result, e.g. item 1, but I get both.
> > 
> > Another approach:
> > 
> > $ curl -XPOST '[http://localhost:9200/test/\_search](http://localhost:9200/test/_search)' -d '{  
> > "query" : {  
> > "terms" : { "securitylevels.usergroupcontentaccess" : [1,1,100],  
> > "minimum\_match" : "3" }  
> > }  
> > }'
> > 
> > Gives me also both records.
> > 
> > What do I miss? I'm using ES 0.9.0RC2
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> Met vriendelijke groet,
> 
> Martijn van Groningen

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:40am UTC](https://discuss.elastic.co/t/filtering-on-acls-do-not-get-the-expected-result/11627/4 "2017-07-06T02:40:29Z")

</div>


