- Notifications
You must be signed in to change notification settings - Fork 25.6k
[Entitlements] Add support for IT testing always allowed actions #124195
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
ldematte merged 3 commits into elastic:main from ldematte:entitlements/test-always-allowed-actions Mar 8, 2025
Merged
[Entitlements] Add support for IT testing always allowed actions #124195
ldematte merged 3 commits into elastic:main from ldematte:entitlements/test-always-allowed-actions Mar 8, 2025
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Collaborator
| Pinging @elastic/es-core-infra (Team:Core/Infra) |
rjernst reviewed Mar 7, 2025
...-plugin/src/main/java/org/elasticsearch/entitlement/qa/test/RestEntitlementsCheckAction.java Outdated Show resolved Hide resolved
rjernst approved these changes Mar 8, 2025
Member
rjernst left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
ldematte added a commit to ldematte/elasticsearch that referenced this pull request Mar 8, 2025
This was referenced Mar 8, 2025
ldematte added a commit to ldematte/elasticsearch that referenced this pull request Mar 8, 2025
Collaborator
ldematte added a commit to ldematte/elasticsearch that referenced this pull request Mar 8, 2025
elasticsearchmachine pushed a commit that referenced this pull request Mar 8, 2025
elasticsearchmachine pushed a commit that referenced this pull request Mar 8, 2025
elasticsearchmachine pushed a commit that referenced this pull request Mar 8, 2025
georgewallace pushed a commit to georgewallace/elasticsearch that referenced this pull request Mar 11, 2025
ldematte added a commit that referenced this pull request Mar 12, 2025
…ke 2) (#124429) Writing tests for #123861, turns out that #124195 is not enough. We really need new IT test cases for "always allowed" actions: in order to be sure they are allowed, we need to setup the plugin with no policy. This PR adds test cases for that, plus the support for writing test functions that accept one Environment parameter: many test paths we test and allow/deny are relative to paths in Environment, so it's useful to have access to it (see readAccessConfigDirectory as an example)
ldematte added a commit to ldematte/elasticsearch that referenced this pull request Mar 12, 2025
…ke 2) (elastic#124429) Writing tests for elastic#123861, turns out that elastic#124195 is not enough. We really need new IT test cases for "always allowed" actions: in order to be sure they are allowed, we need to setup the plugin with no policy. This PR adds test cases for that, plus the support for writing test functions that accept one Environment parameter: many test paths we test and allow/deny are relative to paths in Environment, so it's useful to have access to it (see readAccessConfigDirectory as an example)
elasticsearchmachine pushed a commit that referenced this pull request Mar 12, 2025
…ke 2) (#124429) (#124627) Writing tests for #123861, turns out that #124195 is not enough. We really need new IT test cases for "always allowed" actions: in order to be sure they are allowed, we need to setup the plugin with no policy. This PR adds test cases for that, plus the support for writing test functions that accept one Environment parameter: many test paths we test and allow/deny are relative to paths in Environment, so it's useful to have access to it (see readAccessConfigDirectory as an example)
ldematte added a commit to ldematte/elasticsearch that referenced this pull request Mar 13, 2025
…ke 2) (elastic#124429) Writing tests for elastic#123861, turns out that elastic#124195 is not enough. We really need new IT test cases for "always allowed" actions: in order to be sure they are allowed, we need to setup the plugin with no policy. This PR adds test cases for that, plus the support for writing test functions that accept one Environment parameter: many test paths we test and allow/deny are relative to paths in Environment, so it's useful to have access to it (see readAccessConfigDirectory as an example)
ldematte added a commit to ldematte/elasticsearch that referenced this pull request Mar 13, 2025
…ke 2) (elastic#124429) Writing tests for elastic#123861, turns out that elastic#124195 is not enough. We really need new IT test cases for "always allowed" actions: in order to be sure they are allowed, we need to setup the plugin with no policy. This PR adds test cases for that, plus the support for writing test functions that accept one Environment parameter: many test paths we test and allow/deny are relative to paths in Environment, so it's useful to have access to it (see readAccessConfigDirectory as an example)
elasticsearchmachine pushed a commit that referenced this pull request Mar 13, 2025
…ke 2) (#124429) (#124703) Writing tests for #123861, turns out that #124195 is not enough. We really need new IT test cases for "always allowed" actions: in order to be sure they are allowed, we need to setup the plugin with no policy. This PR adds test cases for that, plus the support for writing test functions that accept one Environment parameter: many test paths we test and allow/deny are relative to paths in Environment, so it's useful to have access to it (see readAccessConfigDirectory as an example)
elasticsearchmachine pushed a commit that referenced this pull request Mar 13, 2025
…ke 2) (#124429) (#124704) Writing tests for #123861, turns out that #124195 is not enough. We really need new IT test cases for "always allowed" actions: in order to be sure they are allowed, we need to setup the plugin with no policy. This PR adds test cases for that, plus the support for writing test functions that accept one Environment parameter: many test paths we test and allow/deny are relative to paths in Environment, so it's useful to have access to it (see readAccessConfigDirectory as an example)
albertzaharovits pushed a commit to albertzaharovits/elasticsearch that referenced this pull request Mar 13, 2025
…ke 2) (elastic#124429) Writing tests for elastic#123861, turns out that elastic#124195 is not enough. We really need new IT test cases for "always allowed" actions: in order to be sure they are allowed, we need to setup the plugin with no policy. This PR adds test cases for that, plus the support for writing test functions that accept one Environment parameter: many test paths we test and allow/deny are relative to paths in Environment, so it's useful to have access to it (see readAccessConfigDirectory as an example)
jfreden pushed a commit to jfreden/elasticsearch that referenced this pull request Mar 13, 2025
…ke 2) (elastic#124429) Writing tests for elastic#123861, turns out that elastic#124195 is not enough. We really need new IT test cases for "always allowed" actions: in order to be sure they are allowed, we need to setup the plugin with no policy. This PR adds test cases for that, plus the support for writing test functions that accept one Environment parameter: many test paths we test and allow/deny are relative to paths in Environment, so it's useful to have access to it (see readAccessConfigDirectory as an example)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
auto-backport Automatically create backport pull requests when merged :Core/Infra/Entitlements Entitlements infrastructure Team:Core/Infra Meta label for core/infra team >test Issues or PRs that are addressing/adding tests v8.18.1 v8.19.0 v9.0.1 v9.1.0
Add this suggestion to a batch that can be applied as a single commit. This suggestion is invalid because no changes were made to the code. Suggestions cannot be applied while the pull request is closed. Suggestions cannot be applied while viewing a subset of changes. Only one suggestion per line can be applied in a batch. Add this suggestion to a batch that can be applied as a single commit. Applying suggestions on deleted lines is not supported. You must change the existing code in this line in order to create a valid suggestion. Outdated suggestions cannot be applied. This suggestion has been applied or marked resolved. Suggestions cannot be applied from pending reviews. Suggestions cannot be applied on multi-line comments. Suggestions cannot be applied while the pull request is queued to merge. Suggestion cannot be applied right now. Please check back later.
While implementing #124111 I realized we do not have (currently) a way to write a IT test to ensure that "always allowed" actions can be performed even when there is no policy/no entitlement for them.
One example is access to specific, always allowed directories.
This PR adds a new IT test class to run tests for actions that should always be allowed.