we are using readonlyrest 1.16.33 on ES 6.5.4, with an LDAP backend, and have noticed an odd behavior where the user’s Kibana session suddenly switches to that of the Kibana server user, under certain conditions. For example:
ldap user logs on to Kibana
chooses the Monitoring tab on the left hand pane
he then chooses a different role via the multi-tenancy drop-down at the top left; note that the chosen role has no access to the Monitoring tab - it is hidden
4.the user’s Kibana session is then switched to the Kibana server session
We have since tried upgrading to 1.16.34 in the hope that would fix the issue. It did not.
Now that you describe the issue in the details, I think I know what’s going on. What happens when after point 4, the user clicks on another app, like for example timelion?
Working on this right now. The 6.6.x got the priority because it was much easier to fix there, and it’s newer. Previous versions need a bit more attention.
can you please confirm, if there is a fix out for 6.5.4? Sounds like that is the case, just looking for a confirmation before we request and install the updated plugin.
I tried to reproduce this again, with no success using ROR Enterprise 1.17.4 for Kibana 6.5.4.
I also opened the zip file to see if the fix was in place. and it is.
Is the test case above still valid or do you do now something different?
yes, the above test case is still valid. For example we have user1, which is an ldap user that is part of both administrators and developers groups, as below.
user1 logs on to Kibana, multi-tenancy defaults to the administrators role
user1 then goes to the Monitoring tab (correct username is reflected at bottom right)
user1 then chooses the developers role from the multi-tenancy drop-down (to which the role has no access to)
at this point the session is switched to the user context of kibana server, which is reflected at the bottom left corner. The session remains this way until the user is logged off.
I did test all the other tabs, and it appears this only happens with the Monitoring tab. For all the other tabs that are hidden from the developers role, the user is just taken to the main Kibana landing page without the session being switched.
$ grep version plugins/readonlyrest_kbn/package.json
I tried your test case with no luck even outside the dev environemnt. I just downloaded Kibana 6.5.4 from the website, the 1.17.4 Enterprise plugin, login, I’m in role administrators, go to monitoring, change to developers and I’m redirected to Kibana home and all is normal.
Another way to check if the fix is not there for some reason: