Skip to content

Commit f5a1bc2

Browse files
audit "access denied" only when we actually return access denied error
1 parent c285c8c commit f5a1bc2

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/authz/AuthorizationService.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -503,12 +503,12 @@ private void authorizeAction(
503503
indicesAndAliasesResolver.resolve(action, request, projectMetadata, authorizedIndices)
504504
),
505505
e -> {
506-
auditTrail.accessDenied(requestId, authentication, action, request, authzInfo);
507506
if (e instanceof IndexNotFoundException
508507
|| e instanceof InvalidIndexNameException
509508
|| e instanceof IllegalArgumentException) {
510509
listener.onFailure(e);
511510
} else {
511+
auditTrail.accessDenied(requestId, authentication, action, request, authzInfo);
512512
listener.onFailure(actionDenied(authentication, authzInfo, action, request, e));
513513
}
514514
}

0 commit comments

Comments
 (0)