Conversation
Signed-off-by: Nils Bandener <nils.bandener@eliatra.com>
PR Reviewer Guide 🔍Here are some key observations to aid the review process:
|
PR Code Suggestions ✨Explore these optional code suggestions:
|
|
@cwperks @DarshitChanpura @Bukhtawar @niravpi Please have a look at this. It should already be the complete implementation. I left it in draft state, because we have to coordinate merging on the core and security side. |
|
❕ Gradle check result for 5a3ce6c: UNSTABLE Please review all flaky tests that succeeded after retry and create an issue if one does not already exist to track the flaky failure. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #23168 +/- ##
============================================
+ Coverage 71.81% 71.83% +0.02%
- Complexity 77894 77910 +16
============================================
Files 6183 6183
Lines 361063 361066 +3
Branches 52555 52555
============================================
+ Hits 259295 259371 +76
+ Misses 81189 81134 -55
+ Partials 20579 20561 -18 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Signed-off-by: Nils Bandener <nils.bandener@eliatra.com>
PR Code Analyzer ❗AI-powered 'Code-Diff-Analyzer' found issues on commit 01f316a. ⛔ Hard block: Issues at Medium severity or above will block this PR from merging.
The table above displays the top 10 most important findings. Pull Requests Author(s): Please update your Pull Request according to the report above. Repository Maintainer(s): You can Thanks. |
Description
Adds logical-plan DLS enforcement for analytics queries according to RFC spec in #22756 .
This introduces the plugin interface
AccessPolicyProviderPluginand the injectableReadAccessPolicyService.The
AccessPolicyProviderPluginwill be implemented by the security plugin in the separate PR opensearch-project/security#6569The analytics plugins resolve the concrete indices referenced by a logical plan, obtains the effective policy from
ReadAccessPolicyService., and rewrites protected table scans before planning/execution:UNION ALL;RexSubQueryexpressions are also rewritten.dsl-query-executorprovides the QueryBuilder-to-Calcite translation SPI used by the rewrite.Notes
When analytics selects the Lucene backend, DLS is enforced both at the logical-query level and at the existing Lucene level. This is intentional in order avoid weakening the established Lucene DLS protection for normal search execution.
The implementation fails closed in case a DLS query uses a query type that cannot be translated to the target query language.
FLS and field masking will follow in a separate PR.
Tests
match_none, missing translators, andRexSubQueryrewriting.AccessPolicyProviderPlugin, covering both a restricted and an unrestricted user policy.Check List
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.