# jQuery Autocomplete and security injection in a multi-tenanted environment

**URL:** <https://discuss.elastic.co/t/jquery-autocomplete-and-security-injection-in-a-multi-tenanted-environment/4150>\
**Category:** Elasticsearch\
**Created:** [March 23, 2011, 4:55am UTC](https://discuss.elastic.co/t/jquery-autocomplete-and-security-injection-in-a-multi-tenanted-environment/4150 "2011-03-23T04:55:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_smith/32/1323_2.png) [@Paul\_Smith](https://discuss.elastic.co/u/Paul_Smith)\
**Post date:** [March 23, 2011, 4:55am UTC](https://discuss.elastic.co/t/jquery-autocomplete-and-security-injection-in-a-multi-tenanted-environment/4150/1 "2011-03-23T04:55:48Z")

</div>

Following up from a tweet kimchy did about the jQuery autocomplete  
integration with ElasticSearch, I wondered how I would do the same thing,  
but automatically inject on an application layer a 'security' filter.

In our multi-tenanted case we could never expose our ES instance out to the  
wild because it combines data between parties and certain people could only  
see certain slices of that data (done via a 'security' filter).

One _could_ embed the security filter into the jQuery autocomplete snippet  
but obviously anyone with half a brain could easily just strip that out...

So for performance reasons I would like the UI to do the jQuery autocomplete  
and send that ajax call to our application tier, which takes that, converts  
it back to a Java object version of the query object, injects the  
appropriate security filter for this user and submits it to the internal ES  
instance. The result stream could just be streamed back direct to the  
client browser.

Can someone point out where in the source code is the JSon structure of a  
request to ES converted back to object form.. I'm going blind, again. Is it  
the XContentIndexQueryParser ? I'd only want the object that can convert it  
back to Java object form without needing all the other ES internals that  
object requires.

But other than that, is there a different pattern someone else has tried for  
this sort of thing? Most autocomplete stuff I've seen with ES implies a  
direct connect to the ES instance, which in this case isn't a good idea.

cheers,

Paul

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [March 23, 2011, 10:04am UTC](https://discuss.elastic.co/t/jquery-autocomplete-and-security-injection-in-a-multi-tenanted-environment/4150/2 "2011-03-23T10:04:04Z")

</div>

Confused a bit, if you are after converting a Json search request to a Java "SearchSource", then there is no such code, since its not needed in elasticsearch.

You can simplify the jquery part, have it send what you need (the query), and build the search request out of it. Another option is to munge the json you get and pass it to elasticsearch (though, Java is probably the worst language to munge things like json).  
On Wednesday, March 23, 2011 at 6:55 AM, Paul Smith wrote:

> Following up from a tweet kimchy did about the jQuery autocomplete integration with Elasticsearch, I wondered how I would do the same thing, but automatically inject on an application layer a 'security' filter.
> 
> In our multi-tenanted case we could never expose our ES instance out to the wild because it combines data between parties and certain people could only see certain slices of that data (done via a 'security' filter).
> 
> One _could_ embed the security filter into the jQuery autocomplete snippet but obviously anyone with half a brain could easily just strip that out...
> 
> So for performance reasons I would like the UI to do the jQuery autocomplete and send that ajax call to our application tier, which takes that, converts it back to a Java object version of the query object, injects the appropriate security filter for this user and submits it to the internal ES instance. The result stream could just be streamed back direct to the client browser.
> 
> Can someone point out where in the source code is the JSon structure of a request to ES converted back to object form.. I'm going blind, again. Is it the XContentIndexQueryParser ? I'd only want the object that can convert it back to Java object form without needing all the other ES internals that object requires.
> 
> But other than that, is there a different pattern someone else has tried for this sort of thing? Most autocomplete stuff I've seen with ES implies a direct connect to the ES instance, which in this case isn't a good idea.
> 
> cheers,
> 
> Paul

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:09am UTC](https://discuss.elastic.co/t/jquery-autocomplete-and-security-injection-in-a-multi-tenanted-environment/4150/3 "2017-07-06T04:09:23Z")

</div>


