Conversation
Signed-off-by: Nils Bandener <nils.bandener@eliatra.com>
PR Reviewer Guide 🔍Here are some key observations to aid the review process:
|
PR Code Suggestions ✨Explore these optional code suggestions:
|
|
@cwperks @DarshitChanpura @Bukhtawar @niravpi Please have a look at this. It should already be the complete implementation. I left it in draft state, because we have to coordinate merging on the core and security side (at the moment compilation fails because it is missing the new interfaces introduced in core). |
Description
Adds logical-plan DLS enforcement for analytics queries according to RFC spec in #22756 .
This implements the security plugin side of the core PR opensearch-project/OpenSearch#23168 .
It mostly boils down to exposing DLS rules via the
AccessPolicyProviderPlugininterface.Testing
match_none), combined role queries, grouped restrictions, and overlapping-group rejection.ReadAccessPolicyService. They verify the actual Security provider returns the expected restriction for a DLS user and no restriction for an unrestricted user.AccessPolicyProviderPluginto validate analytics enforcement independently of the Security plugin.Check List
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.