3 ms·
I mean, it shouldn't really be very easy to even get a read-write token to a production database, unless you're a correctly-launched instance of a publisher ser
by partdavid 4y ago
I mean, it shouldn't really be very easy to even get a read-write token to a production database, unless you're a correctly-launched instance of a publisher service. This screams to me that they're ignorant of, and probably very sloppy with, access control up and down their stack.
- thayne 4y agoThis is actually discussed in the article. Basically, at least with older versions of elasticsearch, without X-pack elasticsearch didn't have granular permissions. Either you had access or you didn't.
- twblalock 4y agoThis is when you put a gateway-type layer on top of a datastore that enforces your own company-specific authn/authz. In this case, the datastore uses a REST API, so that should be fairly easy to implement. You could even do it in Nginx or Envoy.