Skip to content

Preserve authentication for self-referential CCS - #6474

Merged
willyborankin merged 2 commits into
opensearch-project:mainfrom
cwperks:fix/ccs-self-remote-auth
Sep 14, 2026
Merged

willyborankin merged 2 commits into
opensearch-project:mainfrom
cwperks:fix/ccs-self-remote-auth

Conversation

@cwperks

@cwperks cwperks commented Sep 5, 2026

Copy link
Copy Markdown
Member

Fixes #5846

Summary

  • identify direct local transport requests by the exact local DiscoveryNode instance rather than DiscoveryNode.equals
  • serialize user context for equal-but-distinct remote node representations, including self-referential CCS
  • add regression coverage for a remote connection whose DiscoveryNode equals, but is not identical to, the local node

Validation

  • ./gradlew spotlessJavaCheck test --tests org.opensearch.security.transport.SecurityInterceptorTests --tests org.opensearch.security.transport.RestoringTransportResponseHandlerTests
  • reproduced with two OpenSearch 3.7.0 clusters and both self-referential and external remote aliases
  • before fix: self CCS returned HTTP 500 in 5/5 requests; external CCS returned HTTP 200
  • after identity-based fix: self CCS returned HTTP 200 in 5/5 requests; external CCS returned HTTP 200 in 3/3 requests

Note

  • ./gradlew precommit reaches an unrelated existing forbidden-API failure in the sample resource plugin for URL.openStream()

@github-actions

github-actions Bot commented Sep 5, 2026 •

Copy link
Copy Markdown
Contributor

PR Reviewer Guide 🔍

(Review updated until commit 7427efb)

Here are some key observations to aid the review process:

🧪 PR contains tests
🔒 No security concerns identified
✅ No TODO sections
🔀 No multiple PR themes
⚡ No major issues detected

Identify direct local requests using the TransportService connection instead of relying on DiscoveryNode equality. This ensures remote TCP requests targeting the same node serialize their user context.

Signed-off-by: Craig Perkins <craig5008@gmail.com>
@cwperks
cwperks force-pushed the fix/ccs-self-remote-auth branch from 813bfbb to 1815de0 Compare September 5, 2026 12:34
@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Persistent review updated to latest commit 1815de0

@codecov

codecov Bot commented Sep 5, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 75.93%. Comparing base (65437fa) to head (7427efb).
⚠️ Report is 5 commits behind head on main.

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #6474      +/-   ##
==========================================
+ Coverage   75.88%   75.93%   +0.05%     
==========================================
  Files         459      459              
  Lines       30619    30619              
  Branches     4602     4602              
==========================================
+ Hits        23234    23251      +17     
+ Misses       5265     5248      -17     
  Partials     2120     2120              
Files with missing lines Coverage Δ
.../opensearch/security/OpenSearchSecurityPlugin.java 84.12% <100.00%> (ø)
...search/security/transport/SecurityInterceptor.java 81.88% <100.00%> (ø)

... and 10 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Signed-off-by: Craig Perkins <cwperx@amazon.com>
@github-actions

Copy link
Copy Markdown
Contributor

Persistent review updated to latest commit 7427efb

@willyborankin
willyborankin merged commit b113e77 into opensearch-project:main Sep 14, 2026
68 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] Cross Cluster Search to same node fails auth

2 participants