Rollup_search requires more than read-only permissions #50245
Labels
>bug
:Security/Authorization
Roles, Privileges, DLS/FLS, RBAC/ABAC
:StorageEngine/Rollup
Turn fine-grained time-based data into coarser-grained data
v6.8.0
v7.5.1
In searches against rollup indices using the
_rollup_search
api, users need at leastmanage
privileges for what should really be aread
only operation.This was reported on 6.8 and I reproduced it but this may apply to other versions too.
It's possible
read
andview_index_metadata
may be required privileges but write-capable permissions should really not be required here.The text was updated successfully, but these errors were encountered: