Skip to content

Deprecate filter_by_backend_roles, targeting removal in 4.0 - #1490

Open
DarshitChanpura wants to merge 3 commits into
opensearch-project:mainfrom
DarshitChanpura:deprecate-filter-by-backend-roles
Open

DarshitChanpura wants to merge 3 commits into
opensearch-project:mainfrom
DarshitChanpura:deprecate-filter-by-backend-roles

Conversation

@DarshitChanpura

Copy link
Copy Markdown
Member

Description

Marks backend-role filtering deprecated, targeting removal in 4.0. It is superseded by the security plugin's resource sharing and access control, which authorizes a resource by the access level it is shared at rather than by backend-role overlap, and both workflow and workflow_state are already onboarded.

  • plugins.flow_framework.filter_by_backend_roles gets Setting.Property.Deprecated
  • javadoc records the 4.0 target and the replacement

No behavior change: Property.Deprecated only emits a deprecation warning when the setting is set.

Testing

compileJava is clean. The test task cannot run on this branch: testRuntimeClasspath resolution fails with conflicting jackson-databind (3.2.1 against 3.2.2) and httpclient5 (5.6.1 against 5.6.4) versions. That reproduces with this change stashed, so it is a pre-existing issue on main rather than something this PR introduces. CI will exercise the suite once resolution is fixed.

Related

Tracking issue: opensearch-project/security#6530

Check List

  • Commits are signed per the DCO using --signoff
  • New functionality has been documented — n/a, deprecation only

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

Backend-role filtering is superseded by the security plugin's resource sharing
and access control, which authorizes a resource by the access level it is shared
at rather than by backend-role overlap. Workflows and workflow state are
onboarded to resource sharing, so the setting is now the legacy path.

- plugins.flow_framework.filter_by_backend_roles gets
  Setting.Property.Deprecated
- javadoc names 4.0 as the removal target and the replacement

Verified by compiling; the test task cannot run on this branch because
testRuntimeClasspath resolution fails on main with conflicting jackson-databind
and httpclient5 versions, which reproduces with this change stashed.

Tracking: opensearch-project/security#6530
Signed-off-by: Darshit Chanpura <dchanp@amazon.com>
Signed-off-by: Darshit Chanpura <dchanp@amazon.com>
@github-actions

github-actions Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

PR Reviewer Guide 🔍

(Review updated until commit 356f368)

Here are some key observations to aid the review process:

🧪 No relevant tests
🔒 No security concerns identified
✅ No TODO sections
🔀 No multiple PR themes
⚡ No major issues detected

@github-actions

Copy link
Copy Markdown
Contributor

Persistent review updated to latest commit f61c14b

@github-actions

Copy link
Copy Markdown
Contributor

Persistent review updated to latest commit f61c14b

@github-actions

Copy link
Copy Markdown
Contributor

Persistent review updated to latest commit 356f368

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants