Skip to content

Commit 0793fa2

Browse files
committed
Comment
1 parent b96ada0 commit 0793fa2

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/authz/AuthorizationDenialMessages.java

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -100,10 +100,13 @@ public String actionDenied(
100100
+ "]";
101101
}
102102
} else if (isIndexAction(action)) {
103+
// this includes `all`
103104
final Collection<String> privileges = findIndexPrivilegesThatGrant(
104105
action,
105106
p -> p.getSelectorPredicate().test(IndexComponentSelector.DATA)
106107
);
108+
// this is an invariant since `all` is included in the above so the only way
109+
// we can get an empty result here is a bogus action, which will never be covered by a failures privilege
107110
assert false == privileges.isEmpty()
108111
|| findIndexPrivilegesThatGrant(
109112
action,

0 commit comments

Comments
 (0)