You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在OpenSearch Dashboards插件的Node.js服务器实现授权?

解决方案:在OpenSearch Dashboards插件Node.js层复用用户权限数据

1. 从核心上下文直接获取用户认证信息

OpenSearch Dashboards的context参数中已经包含了已登录用户的完整认证数据,你可以通过context.core.authc直接提取roles和backend_roles,无需额外调用Security API。

修改你的路由代码如下:

router.get(
    {
        path: `...`,
        validate: false,
    },
    async (context, request, response) => {
        try {
            // 获取当前已认证用户信息
            const user = context.core.authc.getCurrentUser();
            if (!user) {
                return response.unauthorized({ body: '未登录用户无法访问' });
            }

            // 提取用户角色与后端角色
            const { roles, backend_roles } = user;

            // 自定义权限校验逻辑示例
            if (!roles.includes('required_access_role')) {
                return response.forbidden({ body: '无此资源访问权限' });
            }

            // 执行后续业务逻辑
            const indices = await yourBusinessLogic();

            return response.ok({
                body: indices,
            });
        } catch (error: any) {
            return response.customError({
                statusCode: 500,
                body: error.message || '服务器内部错误'
            });
        }
    }
);

2. 正确依赖Security插件实现细粒度权限校验

如果需要验证用户对特定集群/索引的操作权限,可以通过插件依赖机制引入Security插件的核心服务,而非直接调用API。

步骤1:声明插件依赖

在你的插件plugin.ts中添加对Security插件的依赖声明:

import type { PluginInitializerContext } from '../../../src/core/server';
import { YourPluginPlugin } from './plugin';

export function plugin(initializerContext: PluginInitializerContext) {
  return new YourPluginPlugin(initializerContext);
}

export const config = {
  exposeToBrowser: {},
};

// 声明依赖Security插件
export const dependencies = ['security'];

步骤2:注入并使用Security授权服务

在插件类中注入Security插件的授权服务,实现细粒度权限校验:

import type { SecurityPluginSetup } from '../../security/server';

export class YourPluginPlugin {
  constructor(private readonly initializerContext: PluginInitializerContext) {}

  public setup(core: CoreSetup, plugins: { security: SecurityPluginSetup }) {
    const router = core.http.createRouter();
    // 获取Security插件的授权服务
    const authzService = plugins.security.authz;

    router.get(
      { path: '...', validate: false },
      async (context, request, response) => {
        try {
          // 校验集群级权限(示例:集群监控权限)
          const hasClusterPerm = await authzService.checkClusterPermission(
            context,
            { cluster: ['cluster:monitor/nodes/info'] }
          );

          // 校验索引级权限(示例:索引读权限)
          const hasIndexPerm = await authzService.checkIndexPermission(
            context,
            { index: ['indices:data/read/search'] },
            ['your_index_pattern*']
          );

          if (!hasClusterPerm || !hasIndexPerm) {
            return response.forbidden({ body: '无对应操作权限' });
          }

          // 执行业务逻辑并返回结果
          return response.ok({ body: '操作允许' });
        } catch (error) {
          return response.customError({ statusCode: 500, body: error.message });
        }
      }
    );

    return {};
  }

  public start(core: CoreStart) {
    return {};
  }
}

3. 方案优势说明

上述两种方式均复用了OpenSearch Dashboards已完成的认证会话,无需给用户额外配置/_plugins/_security/api/account的访问权限,完全契合你的需求。需要注意的是,确保运行插件的OpenSearch Dashboards实例已启用Security插件,且用户通过Security插件完成登录认证。

内容的提问来源于stack exchange,提问作者Some_Person

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 20:05:19