寻找测试无角色Elasticsearch用户身份验证的合适端点
验证Elasticsearch用户身份的无权限端点
可以使用Elasticsearch内置的/_security/_authenticate端点,这个端点专门用于验证当前请求的用户身份,无需任何额外角色权限,完全匹配你的需求:
- 用户名和密码正确时,返回
200 OK,同时返回用户的基础身份信息 - 用户名不存在或密码错误时,返回
401 Unauthorized
请求示例
curl --basic --user your_username:your_password https://evil.com:9200/_security/_authenticate
响应说明
- 验证成功(200)的典型响应:
{ "username" : "your_username", "roles" : ["your_assigned_roles"], "full_name" : null, "email" : null, "metadata" : {}, "enabled" : true } - 验证失败(401)的典型响应:
{ "error": { "root_cause": [ { "type": "security_exception", "reason": "unable to authenticate user [invalid_user] for REST request [/_security/_authenticate]", "header": { "WWW-Authenticate": "Basic realm=\"security\" charset=\"UTF-8\"" } } ], "type": "security_exception", "reason": "unable to authenticate user [invalid_user] for REST request [/_security/_authenticate]", "header": { "WWW-Authenticate": "Basic realm=\"security\" charset=\"UTF-8\"" } }, "status": 401 }
这个端点避开了需要特定角色权限的资源接口,直接聚焦身份验证逻辑,通过状态码就能直观判断验证结果,完全符合你想要的测试方式。
内容的提问来源于stack exchange,提问作者gavenkoa
相关产品推荐
相关产品推荐

