From a73424d6af55528531ca70fbcec9e36c86e5d62c Mon Sep 17 00:00:00 2001 From: wvl Date: Tue, 13 Sep 2016 15:04:21 +0200 Subject: [PATCH] Secure Elasticsearch datasources a bit (#6031) Instead of allowing users to access the entire cluster, apply some sane restrictions. Change-Id: Ib2e93722bf2e39d700d4afa713ff49ec556f2fdf --- pkg/api/dataproxy.go | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/pkg/api/dataproxy.go b/pkg/api/dataproxy.go index 66d654d4d93..97f2529c781 100644 --- a/pkg/api/dataproxy.go +++ b/pkg/api/dataproxy.go @@ -104,6 +104,22 @@ func ProxyDataSourceRequest(c *middleware.Context) { } proxyPath := c.Params("*") + + if ds.Type == m.DS_ES { + if c.Req.Request.Method == "DELETE" { + c.JsonApiErr(403, "Deletes not allowed on proxied Elasticsearch datasource", nil) + return + } + if c.Req.Request.Method == "PUT" { + c.JsonApiErr(403, "Puts not allowed on proxied Elasticsearch datasource", nil) + return + } + if c.Req.Request.Method == "POST" && proxyPath != "_msearch" { + c.JsonApiErr(403, "Posts not allowed on proxied Elasticsearch datasource except on /_msearch", nil) + return + } + } + proxy := NewReverseProxy(ds, proxyPath, targetUrl) proxy.Transport = dataProxyTransport proxy.ServeHTTP(c.Resp, c.Req.Request)