[Backport] Add manage_own_api_key
cluster privilege (#45897)
#46023
+1,768
−741
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The existing privilege model for API keys with privileges like
manage_api_key
,manage_security
etc. are too permissive andwe would want finer-grained control over the cluster privileges
for API keys. Previously APIs created would also need these
privileges to get its own information.
This commit adds support for
manage_own_api_key
cluster privilegewhich only allows api key cluster actions on API keys owned by the
currently authenticated user. Also adds support for retrieval of
the API key self-information when authenticating via API key
without the need for the additional API key privileges.
To support this privilege, we are introducing additional
authentication context along with the request context such that
it can be used to authorize cluster actions based on the current
user authentication.
The API key get and invalidate APIs introduce an
owner
flagthat can be set to true if the API key request (Get or Invalidate)
is for the API keys owned by the currently authenticated user only.
In that case,
realm
andusername
cannot be set as they areassumed to be the currently authenticated ones.
The changes cover HLRC changes, documentation for the API changes.
Closes #40031