# How can a search request be intercepted/modified?

**URL:** <https://discuss.elastic.co/t/how-can-a-search-request-be-intercepted-modified/14002>\
**Category:** Elasticsearch\
**Created:** [October 17, 2013, 9:39pm UTC](https://discuss.elastic.co/t/how-can-a-search-request-be-intercepted-modified/14002 "2013-10-17T21:39:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hendrik](https://avatars.discourse-cdn.com/v4/letter/h/839c29/32.png) [@Hendrik](https://discuss.elastic.co/u/Hendrik)\
**Post date:** [October 17, 2013, 9:39pm UTC](https://discuss.elastic.co/t/how-can-a-search-request-be-intercepted-modified/14002/1 "2013-10-17T21:39:19Z")

</div>

Hi,

i want (at the end) limit the fields which are returned in a search  
response for security purposes (so this should be enforced on the server  
side).  
My first idea to archieve this is to hook into the search request (with a  
plugin) and modifiy the request and add some "fields" : ["allowedfield1",  
"allowedfield2"]  
But i have problems to find the right point to "hook in". Maybe this  
approach is not really possible? Maybe then an alternative is to implement  
my own endpoint ("\_limitedsearch" for example) and borrow some code  
from org.elasticsearch.rest.action.search.RestSearchAction

Another interesting option is the SearchServiceListener, but here i ca only  
modify the result which is harder and maybe has a performance drawback.

Any clues?

Thanks  
Hendrik

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Lukas\_Vlcek1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas_vlcek1/32/819_2.png) [@Lukas\_Vlcek1](https://discuss.elastic.co/u/Lukas_Vlcek1)\
**Post date:** [October 18, 2013, 6:19am UTC](https://discuss.elastic.co/t/how-can-a-search-request-be-intercepted-modified/14002/2 "2013-10-18T06:19:48Z")

</div>

You can do it on proxy. Ie. after you get the final response from ES and  
before you hand it to the client. That is very clean solution IMO.

Regards,  
Lukáš  
Dne 17.10.2013 23:39 "Hendrik" [h.j.saly@googlemail.com](mailto:h.j.saly@googlemail.com) napsal(a):

> Hi,
> 
> i want (at the end) limit the fields which are returned in a search  
> response for security purposes (so this should be enforced on the server  
> side).  
> My first idea to archieve this is to hook into the search request (with a  
> plugin) and modifiy the request and add some "fields" : ["allowedfield1",  
> "allowedfield2"]  
> But i have problems to find the right point to "hook in". Maybe this  
> approach is not really possible? Maybe then an alternative is to implement  
> my own endpoint ("\_limitedsearch" for example) and borrow some code  
> from org.elasticsearch.rest.action.search.RestSearchAction
> 
> Another interesting option is the SearchServiceListener, but here i ca  
> only modify the result which is harder and maybe has a performance drawback.
> 
> Any clues?
> 
> Thanks  
> Hendrik
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 20, 2013, 3:39pm UTC](https://discuss.elastic.co/t/how-can-a-search-request-be-intercepted-modified/14002/3 "2013-10-20T15:39:23Z")

</div>

Hey,

are source includes and excludes not sufficient in your case? See

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

If not, I'd be interested what kind of functionality you are missing.

--Alex

On Fri, Oct 18, 2013 at 8:19 AM, Lukáš Vlček [lukas.vlcek@gmail.com](mailto:lukas.vlcek@gmail.com) wrote:

> You can do it on proxy. Ie. after you get the final response from ES and  
> before you hand it to the client. That is very clean solution IMO.
> 
> Regards,  
> Lukáš  
> Dne 17.10.2013 23:39 "Hendrik" [h.j.saly@googlemail.com](mailto:h.j.saly@googlemail.com) napsal(a):
> 
> Hi,
> 
> > i want (at the end) limit the fields which are returned in a search  
> > response for security purposes (so this should be enforced on the server  
> > side).  
> > My first idea to archieve this is to hook into the search request (with a  
> > plugin) and modifiy the request and add some "fields" : ["allowedfield1",  
> > "allowedfield2"]  
> > But i have problems to find the right point to "hook in". Maybe this  
> > approach is not really possible? Maybe then an alternative is to implement  
> > my own endpoint ("\_limitedsearch" for example) and borrow some code  
> > from org.elasticsearch.rest.action.search.RestSearchAction
> > 
> > Another interesting option is the SearchServiceListener, but here i ca  
> > only modify the result which is harder and maybe has a performance drawback.
> > 
> > Any clues?
> > 
> > Thanks  
> > Hendrik
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Hendrik](https://avatars.discourse-cdn.com/v4/letter/h/839c29/32.png) [@Hendrik](https://discuss.elastic.co/u/Hendrik)\
**Post date:** [October 22, 2013, 9:58pm UTC](https://discuss.elastic.co/t/how-can-a-search-request-be-intercepted-modified/14002/4 "2013-10-22T21:58:33Z")

</div>

i need different rules for different clients, see my solution here:  
[https://github.com/salyh/elasticsearch-security-plugin/blob/master/src/main/java/org/elasticsearch/plugins/security/filter/FieldResponseFilter.java](https://github.com/salyh/elasticsearch-security-plugin/blob/master/src/main/java/org/elasticsearch/plugins/security/filter/FieldResponseFilter.java)

Am Sonntag, 20. Oktober 2013 17:39:23 UTC+2 schrieb Alexander Reelsen:

> Hey,
> 
> are source includes and excludes not sufficient in your case? See
> 
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/mapping-source-field.html#include-exclude)
> 
> If not, I'd be interested what kind of functionality you are missing.
> 
> --Alex
> 
> On Fri, Oct 18, 2013 at 8:19 AM, Lukáš Vlček \<[lukas...@gmail.com](mailto:lukas...@gmail.com)\<javascript:\>
> 
> > wrote:
> 
> > You can do it on proxy. Ie. after you get the final response from ES and  
> > before you hand it to the client. That is very clean solution IMO.
> > 
> > Regards,  
> > Lukáš  
> > Dne 17.10.2013 23:39 "Hendrik" \<[h.j....@googlemail.com](mailto:h.j....@googlemail.com) \<javascript:\>\>  
> > napsal(a):
> > 
> > Hi,
> > 
> > > i want (at the end) limit the fields which are returned in a search  
> > > response for security purposes (so this should be enforced on the server  
> > > side).  
> > > My first idea to archieve this is to hook into the search request (with  
> > > a plugin) and modifiy the request and add some "fields" : [  
> > > "allowedfield1", "allowedfield2"]  
> > > But i have problems to find the right point to "hook in". Maybe this  
> > > approach is not really possible? Maybe then an alternative is to implement  
> > > my own endpoint ("\_limitedsearch" for example) and borrow some code  
> > > from org.elasticsearch.rest.action.search.RestSearchAction
> > > 
> > > Another interesting option is the SearchServiceListener, but here i ca  
> > > only modify the result which is harder and maybe has a performance drawback.
> > > 
> > > Any clues?
> > > 
> > > Thanks  
> > > Hendrik
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:11am UTC](https://discuss.elastic.co/t/how-can-a-search-request-be-intercepted-modified/14002/5 "2017-07-06T02:11:08Z")

</div>


