# Shield with Custom REST plugins

**URL:** <https://discuss.elastic.co/t/shield-with-custom-rest-plugins/40499>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 29, 2016, 4:05pm UTC](https://discuss.elastic.co/t/shield-with-custom-rest-plugins/40499 "2016-01-29T16:05:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![leeho](https://avatars.discourse-cdn.com/v4/letter/l/9e8a1a/32.png) [@leeho](https://discuss.elastic.co/u/leeho)\
**Post date:** [January 29, 2016, 4:05pm UTC](https://discuss.elastic.co/t/shield-with-custom-rest-plugins/40499/1 "2016-01-29T16:05:39Z")

</div>

Hi,

We've been scratching our heads at this for a while so we thought we'd give it a shot here.

**Some background:** We have an application that uses ElasticSearch with a custom plugin with a custom REST endpoint that we've written for ElasticSearch 2.1. We have tried the application with the plugin and it works fine. The custom REST endpoint has a structure like so: //\_function?param1=&param2=. We have since tried to get this plugin working with Shield installed on ElasticSearch. We are coming across a problem that Shield is erroring with:

[2016-01-29 16:00:08,062][INFO][rest.suppressed] /index\_test/\_function Params: {field=testfield, size=50, index=index\_test, term=a}  
ElasticsearchSecurityException[action [indices/termlist] is unauthorized for user [user1]]  
at org.elasticsearch.shield.support.Exceptions.authorizationError(Exceptions.java:45)  
at org.elasticsearch.shield.authz.InternalAuthorizationService.denialException(InternalAuthorizationService.java:294)  
at org.elasticsearch.shield.authz.InternalAuthorizationService.denial(InternalAuthorizationService.java:268)  
at org.elasticsearch.shield.authz.InternalAuthorizationService.authorize(InternalAuthorizationService.java:165)  
at org.elasticsearch.shield.action.ShieldActionFilter.apply(ShieldActionFilter.java:105)  
at org.elasticsearch.action.support.TransportAction$RequestFilterChain.proceed(TransportAction.java:99)  
at org.elasticsearch.action.support.TransportAction.execute(TransportAction.java:77)  
at org.elasticsearch.client.node.NodeClient.doExecute(NodeClient.java:58)  
at org.elasticsearch.client.support.AbstractClient.execute(AbstractClient.java:347)  
at org.elasticsearch.client.FilterClient.doExecute(FilterClient.java:52)  
at  
I've tried playing around with the roles.yml file but have had no luck. The user currently has role admin and the roles.yml for admin is as follows:

admin:  
cluster: all  
indices:  
'\*':  
privileges: all

Some advice on how we can fix this would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [February 1, 2016, 6:16pm UTC](https://discuss.elastic.co/t/shield-with-custom-rest-plugins/40499/2 "2016-02-01T18:16:54Z")

</div>

Hi,

I believe you need to change your action name to follow the [standard naming convention](https://github.com/elastic/elasticsearch/blob/6e81b0dd7025fe10d49ade35b5852697ef39355e/core/src/test/java/org/elasticsearch/transport/ActionNamesIT.java) for it to work with shield. That said, it is unknown if shield can properly protect this custom endpoint as we are not aware of what it does and you may encounter other issues when the action does not work with shield.

Jay

---

<div class="post-metadata">

**Author:** ![leeho](https://avatars.discourse-cdn.com/v4/letter/l/9e8a1a/32.png) [@leeho](https://discuss.elastic.co/u/leeho)\
**Post date:** [February 12, 2016, 11:23am UTC](https://discuss.elastic.co/t/shield-with-custom-rest-plugins/40499/3 "2016-02-12T11:23:47Z")

</div>

Thanks Jay. This worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46pm UTC](https://discuss.elastic.co/t/shield-with-custom-rest-plugins/40499/4 "2017-07-06T13:46:56Z")

</div>


