Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cluster alert watch status page can be accesed via the URL #18191

Closed
elasticmachine opened this issue Apr 12, 2018 · 2 comments · Fixed by #35301
Closed

Cluster alert watch status page can be accesed via the URL #18191

elasticmachine opened this issue Apr 12, 2018 · 2 comments · Fixed by #35301
Labels
bug Fixes for quality problems that affect the customer experience Feature:Watcher Team:Kibana Management Dev Tools, Index Management, Upgrade Assistant, ILM, Ingest Node Pipelines, and more

Comments

@elasticmachine
Copy link
Contributor

Original comment by @marius-dr:

The Edit and Status page should be unavailable to the user for the cluster alerts watches. This is true for the Edit page, but the status page can be accessed by using the direct URL to it like this:
Cluster alert watch ID: lgifRU4RTCKjZ-7391mVIQ_elasticsearch_cluster_status
URL: http://localhost:5601/app/kibana#/management/elasticsearch/watcher/watches/watch/lgifRU4RTCKjZ-7391mVIQ_elasticsearch_cluster_status/status?_g=()

You can Activate/Deactivate and even Delete the watch from that page. If you click on the Edit tab, it will show a blank page, so that one is safe from tampering.
We should should block access to this page as well and maybe add a message on it.
watch

@elasticmachine
Copy link
Contributor Author

Original comment by @tsullivan:

We should should block access to this page as well and maybe add a message on it.

If that's going to be the solution then this is more of a Watcher Management issue than a Monitoring one.

I believe the Monitoring cluster alerts have metadata that should be able to signal to Management that these alerts are off-limits

@elasticmachine elasticmachine added Feature:Watcher bug Fixes for quality problems that affect the customer experience labels Apr 25, 2018
@cjcenizal cjcenizal added Team:Kibana Management Dev Tools, Index Management, Upgrade Assistant, ILM, Ingest Node Pipelines, and more and removed :Management DO NOT USE labels May 1, 2019
@elasticmachine
Copy link
Contributor Author

Pinging @elastic/es-ui

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience Feature:Watcher Team:Kibana Management Dev Tools, Index Management, Upgrade Assistant, ILM, Ingest Node Pipelines, and more
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants