# X-Pack Security : Role definition query template with 'terms'

**URL:** <https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790>\
**Category:** Elasticsearch\
**Created:** [October 12, 2016, 8:52am UTC](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790 "2016-10-12T08:52:48Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jennifer\_Wang](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@Jennifer\_Wang](https://discuss.elastic.co/u/Jennifer_Wang)\
**Post date:** [October 12, 2016, 8:52am UTC](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790/1 "2016-10-12T08:52:48Z")

</div>

Hi,

I am evaluating Elastic 5 beta1 X-Pack document level security.

I have user metadata object which has attribute 'groups'. The groups is a list of group names.

Assume I have one user who has \_user.metadata.groups =["a","b"].  
I try to write query template to generate below query:  
{"template":{"inline":{"terms":{"acl.groups":["a", "b"] }}}}

My question is  
How do I pass variable \_user.metadata.groups as "acl.groups' field's value in the template?

Another question about X-Pack security limitation.  
From [https://www.elastic.co/guide/en/x-pack/current/security-limitations.html](https://www.elastic.co/guide/en/x-pack/current/security-limitations.html)  
it said 'The terms query with terms lookup isn’t supported.' Is this only under 'remote' context?  
The 'terms' query is supported for role definition and user search with current cluster?

Thank you in advance for your replies.

Best Regards,

Jenny

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [October 12, 2016, 11:14am UTC](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790/2 "2016-10-12T11:14:25Z")

</div>

Hi Jenny,

> [@Jennifer\_Wang](#):
>
> 'The terms query with terms lookup isn’t supported.' Is this only under 'remote' context?  
> The 'terms' query is supported for role definition and user search with current cluster?

This is only for the case where the query is actually trying to lookup terms in the same index or another index (as in it will execute a search for the terms). The terms query is supported with the terms specified.

In order to template the query for document level security, you can use something like the following:

```
{
  "indices" : [
    {
      "names" : ["my_index"],
      "privileges" : ["read"],
      "query" : {
        "template" : {
          "inline" : {
            "terms" : { "acl.groups" : "{{#toJson}}_user.metadata.groups{{/toJson}}" }
          }
        }
      }
    }
  ]
}

```

The information about was pulled from the following documentation:

> **[Search Template | Elasticsearch Guide \[5.0\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/5.0/search-template.html)**

> **[Setting Up Field and Document Level Security | X-Pack for the Elastic Stack...](https://www.elastic.co/guide/en/x-pack/current/field-and-document-access-control.html)**

---

<div class="post-metadata">

**Author:** ![Jennifer\_Wang](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@Jennifer\_Wang](https://discuss.elastic.co/u/Jennifer_Wang)\
**Post date:** [October 12, 2016, 12:10pm UTC](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790/3 "2016-10-12T12:10:50Z")

</div>

Hi,

Thank you for your quick response.

I did try {#toJson}... before posting this question. I could not make it worked.

I tried again I still have an error when I do /\_search.

Here my role definition  
/\_xpack/security/role/xxx\_user

> {  
> "xxx\_user": {  
> "cluster": ,  
> "indices": [  
> {  
> "names": [  
> "xxx"  
> ],  
> "privileges": [  
> "read"  
> ],  
> "query": "{"template":{"inline":{"terms":{"acl.groups":"{{#toJson}}\_user.metadata.groups{{/toJson}}" }}}}"  
> }  
> ],  
> "run\_as": ,  
> "metadata": {}  
> }  
> }

Here is the error I got from \_search

> {  
> "error": {  
> "root\_cause": [  
> {  
> "type": "parsing\_exception",  
> "reason": "[terms] query does not support [acl.groups]",  
> "line": 1,  
> "col": 24  
> }  
> ],  
> "type": "search\_phase\_execution\_exception",  
> "reason": "all shards failed",  
> "phase": "query",  
> "grouped": true,  
> "failed\_shards": [  
> {  
> "shard": 0,  
> "index": "xxx",  
> "node": "fK79u0DDTzurHANmfur60w",  
> "reason": {  
> "type": "parsing\_exception",  
> "reason": "[terms] query does not support [acl.groups]",  
> "line": 1,  
> "col": 24  
> }  
> }  
> ],  
> "caused\_by": {  
> "type": "parsing\_exception",  
> "reason": "[terms] query does not support [acl.groups]",  
> "line": 1,  
> "col": 24  
> }  
> },  
> "status": 400  
> }

Do you see any anything I need to change? or you need more information?

Thanks!

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [October 12, 2016, 12:41pm UTC](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790/4 "2016-10-12T12:41:38Z")

</div>

I think removing the escaped quotes `\"` around the toJson tag will help. So I'm thinking it would look like:

```
"query": "{\"template\":{\"inline\":{\"terms\":{\"acl.groups\": {{#toJson}}_user.metadata.groups{{/toJson}} }}}}"
```

---

<div class="post-metadata">

**Author:** ![Jennifer\_Wang](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@Jennifer\_Wang](https://discuss.elastic.co/u/Jennifer_Wang)\
**Post date:** [October 12, 2016, 12:47pm UTC](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790/5 "2016-10-12T12:47:32Z")

</div>

Thank you for your quick reply.  
tried this before: {"template":{"inline":{"terms":{"acl.groups":{{#toJson}}\_user.metadata.groups{{/toJson}} }}}}  
Here is the error:  
Unexpected character ('{' (code 123)): was expecting double-quote to start field name

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [October 12, 2016, 1:46pm UTC](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790/6 "2016-10-12T13:46:12Z")

</div>

Thanks for bearing with me. If the value is not quoted then it gets picked up as JSON itself. The whole inline value must be a string for toJson to work:

```
"query": "{\"template\":{\"inline\":\"{\"terms\":{\"acl.groups\": {{#toJson}}_user.metadata.groups{{/toJson}} }}\"}}"

```

Alternatively, the 2.x way still seems to work:

```
"query": "{\"template\":{\"inline\":{\"terms\":{\"acl.groups\": [\"{{#_user.metadata.groups}}\", \"{{.}}\", \"{{/_user.metadata.groups}}\"] }}}}"
```

---

<div class="post-metadata">

**Author:** ![Jennifer\_Wang](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@Jennifer\_Wang](https://discuss.elastic.co/u/Jennifer_Wang)\
**Post date:** [October 12, 2016, 2:26pm UTC](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790/7 "2016-10-12T14:26:29Z")

</div>

From my \_xpack/security/role/xxx\_user, I have

> ` "query": "{\"template\":{\"inline\":\"{\"terms\":{\"acl.groups\":{{#toJson}}_user.metadata.groups{{/toJson}} }}\"}}"`

From \_search, I have

> ```
> {
> "type": "exception",
> "reason": "com.fasterxml.jackson.core.JsonParseException: Unexpected character ('t' (code 116)): was expecting comma to separate Object entries\n at [Source: org.elasticsearch.common.bytes.BytesReference$MarkSupportingStreamInputWrapper@599eb6b9; line: 1, column: 27]"
> },
> 
> ```

It is possible that ES 5 BETA1 X-Pack has an issue with this feature?

I will try 2.x way as well.

---

<div class="post-metadata">

**Author:** ![Jennifer\_Wang](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@Jennifer\_Wang](https://discuss.elastic.co/u/Jennifer_Wang)\
**Post date:** [October 12, 2016, 3:03pm UTC](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790/8 "2016-10-12T15:03:54Z")

</div>

The 2.x way seems work for me.  
To be sure, I would like to see if this template works as I expect.  
Where I can view the query produced by the template?  
I could not find it from slow search log, even I put it on TRACE level.

Also like to know if the 'toJson' format will be supported in later release.

Thanks!

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [October 12, 2016, 3:04pm UTC](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790/9 "2016-10-12T15:04:52Z")

</div>

I think the issue I missed is needing to escape the quotes at more levels; I did it a bit differently by using json format for query, template, inline, and then a string for the value of inline. I confirmed that the following works on beta1:

```
$ curl -XPUT -u elastic 'localhost:9200/_xpack/security/role/terms_tojson' -d '{ "indices": [
{
"names": [
"foo"
],
"privileges": [
"read"
],
"query": {
"template": {
"inline": "{\"terms\":{\"acl.groups\": {{#toJson}}_user.metadata.groups{{/toJson}} }}"
}
}
}
]
}'
Enter host password for user 'elastic':
"role":{"created":true}}

$ curl -u elastic 'localhost:9200/_xpack/security/role/terms_tojson'?pretty
Enter host password for user 'elastic':
{
  "terms_tojson" : {
    "cluster" : [],
    "indices" : [
      {
        "names" : [
          "foo"
        ],
        "privileges" : [
          "read"
        ],
        "query" : "{\"template\":{\"inline\":\"{\\\"terms\\\":{\\\"acl.groups\\\": {{#toJson}}_user.metadata.groups{{/toJson}} }}\"}}"
      }
    ],
    "run_as" : [],
    "metadata" : { }
  }
}

$ curl -XPUT 'localhost:9200/foo/t/1' -d '{ "acl": { "groups": ["a", "c"] } }' -u elastic
Enter host password for user 'elastic':
{"_index":"foo","_type":"t","_id":"1","_version":1,"result":"created","_shards":{"total":2,"successful":1,"failed":0},"created":true}

$ curl -XPUT 'localhost:9200/foo/t/2' -d '{ "acl": { "groups": ["c"] } }' -u elastic
Enter host password for user 'elastic':
{"_index":"foo","_type":"t","_id":"2","_version":1,"result":"created","_shards":{"total":2,"successful":1,"failed":0},"created":true}

$ curl -u elastic -XPUT 'localhost:9200/_xpack/security/user/tojson' -d '{ "password": "changeme", "roles": ["terms_tojson"], "metadata": { "groups": ["a"] } }'
Enter host password for user 'elastic':
{"user":{"created":false}}

$ curl -u tojson 'localhost:9200/foo/_search?pretty'
Enter host password for user 'tojson':
{
  "took" : 40,
  "timed_out" : false,
  "_shards" : {
    "total" : 5,
    "successful" : 5,
    "failed" : 0
  },
  "hits" : {
    "total" : 1,
    "max_score" : 1.0,
    "hits" : [
      {
        "_index" : "foo",
        "_type" : "t",
        "_id" : "1",
        "_score" : 1.0,
        "_source" : {
          "acl" : {
            "groups" : [
              "a",
              "c"
            ]
          }
        }
      }
    ]
  }
}

$ curl -u elastic 'localhost:9200/foo/_search?pretty'
Enter host password for user 'elastic':
{
  "took" : 3,
  "timed_out" : false,
  "_shards" : {
    "total" : 5,
    "successful" : 5,
    "failed" : 0
  },
  "hits" : {
    "total" : 2,
    "max_score" : 1.0,
    "hits" : [
      {
        "_index" : "foo",
        "_type" : "t",
        "_id" : "2",
        "_score" : 1.0,
        "_source" : {
          "acl" : {
            "groups" : [
              "c"
            ]
          }
        }
      },
      {
        "_index" : "foo",
        "_type" : "t",
        "_id" : "1",
        "_score" : 1.0,
        "_source" : {
          "acl" : {
            "groups" : [
              "a",
              "c"
            ]
          }
        }
      }
    ]
  }
}
```

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [October 12, 2016, 3:06pm UTC](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790/10 "2016-10-12T15:06:16Z")

</div>

> [@Jennifer\_Wang](#):
>
> Where I can view the query produced by the template?

I do not believe this is logged anywhere currently.

---

<div class="post-metadata">

**Author:** ![Jennifer\_Wang](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@Jennifer\_Wang](https://discuss.elastic.co/u/Jennifer_Wang)\
**Post date:** [October 12, 2016, 3:35pm UTC](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790/11 "2016-10-12T15:35:59Z")

</div>

This time 'toJson' format works for me.  
I think all my questions answered.  
Thank you for your great support.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:40pm UTC](https://discuss.elastic.co/t/x-pack-security-role-definition-query-template-with-terms/62790/12 "2017-07-06T13:40:22Z")

</div>


