# Update by query rejected despite having index privilege on index alias

**URL:** <https://discuss.elastic.co/t/update-by-query-rejected-despite-having-index-privilege-on-index-alias/272425>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 7, 2021, 1:43pm UTC](https://discuss.elastic.co/t/update-by-query-rejected-despite-having-index-privilege-on-index-alias/272425 "2021-05-07T13:43:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jdmcalee](https://avatars.discourse-cdn.com/v4/letter/j/90ced4/32.png) [@jdmcalee](https://discuss.elastic.co/u/jdmcalee)\
**Post date:** [May 7, 2021, 1:43pm UTC](https://discuss.elastic.co/t/update-by-query-rejected-despite-having-index-privilege-on-index-alias/272425/1 "2021-05-07T13:43:29Z")

</div>

I have a set of concrete indexes named like myindex-v1 with aliases like myindex. For my roles, I've granted privileges as needed to all of the aliases and not the concrete indexes. That all works fine except when I attempt an update by query operation. For that, I get an error like:

```auto
{"index":"myindex-v1","type":"_doc","id":"n84CR3kBdB1sHUuGSQZl","cause":{"type":"security_exception","reason":"action [indices:data/write/bulk[s]] is unauthorized for user [apiuser] run as [logged-in-user]"},"status":403}

```

I am indeed using the run-as functionality, just to confirm the error. The logged-in-user does have the proper role assigned. If I add the concrete index to the index privilege for the role, the update by query operation runs successfully.

Since the concrete index is shown in the error, is there something inherent about update by query that requires privileges on the concrete index, or is this unintended behavior?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 12, 2021, 12:28am UTC](https://discuss.elastic.co/t/update-by-query-rejected-despite-having-index-privilege-on-index-alias/272425/2 "2021-05-12T00:28:48Z")

</div>

> [@jdmcalee](#):
>
> Since the concrete index is shown in the error, is there something inherent about update by query that requires privileges on the concrete index, or is this unintended behavior

The alias will resolved to 1 (or more) underlying indices, so yes it needs access to those for the writes.

---

<div class="post-metadata">

**Author:** ![jdmcalee](https://avatars.discourse-cdn.com/v4/letter/j/90ced4/32.png) [@jdmcalee](https://discuss.elastic.co/u/jdmcalee)\
**Post date:** [May 13, 2021, 12:48pm UTC](https://discuss.elastic.co/t/update-by-query-rejected-despite-having-index-privilege-on-index-alias/272425/3 "2021-05-13T12:48:54Z")

</div>

Thank you for confirming, but in that case, the [update by query API documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-update-by-query.html) is at least misleading, if not flatly incorrect:

> ### Prerequisites
> 
> - If the Elasticsearch security features are enabled, you must have the following [index privileges](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-privileges.html#privileges-list-indices) for the target data stream, index, or index alias:

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2021, 12:49pm UTC](https://discuss.elastic.co/t/update-by-query-rejected-despite-having-index-privilege-on-index-alias/272425/4 "2021-06-10T12:49:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
