Skip to content

[Backport 3.7] Apply Index Monitor API input validation to the Execute Monitor API - #2226

Open
opensearch-ci-bot wants to merge 1 commit into
opensearch-project:3.7from
opensearch-ci-bot:backport/backport-2225-to-3.7
Open

[Backport 3.7] Apply Index Monitor API input validation to the Execute Monitor API#2226
opensearch-ci-bot wants to merge 1 commit into
opensearch-project:3.7from
opensearch-ci-bot:backport/backport-2225-to-3.7

Conversation

@opensearch-ci-bot

Copy link
Copy Markdown
Contributor

Backport 69e265b from #2225.

…pensearch-project#2225)

The Execute Monitor API (POST /_plugins/_alerting/monitors/_execute) did not
apply the same input validation that the Index Monitor API applies when a
monitor is created. This makes the two paths consistent:

- RestExecuteMonitorAction now calls validateDataSources() so an inline
  monitor cannot specify non-default query/findings/alerts indices, matching
  the check already performed by RestIndexMonitorAction.
- TransportExecuteMonitorAction now checks that the caller has read access to
  the inline monitor's configured input indices before stashing the security
  context, mirroring TransportIndexMonitorAction.checkIndicesAndExecute.
  Monitors executed by id are unaffected as they are validated at creation.

Signed-off-by: Jeremy Michael <jsusanto@amazon.com>
Co-authored-by: Jeremy Michael <jsusanto@amazon.com>
(cherry picked from commit 69e265b)
Signed-off-by: opensearch-ci-bot <opensearch-infra@amazon.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants