Skip to content

Commit

Permalink
Add disablePrototypePoisoningProtection configuration (#2992) (#3324)
Browse files Browse the repository at this point in the history
Enables the configuration of `disablePrototypePoisoningProtection` by setting
`opensearch.disablePrototypePoisoningProtection`. Enables users to store
protected logs that include reserve words from JS without the
OpenSearch JS client throwing errors.

We should still consider transforming unsafe data values if a bad actor
attempts to prototype pollute the cluster.

More information:
https://web.archive.org/web/20200319091159/https://hueniverse.com/square-brackets-are-the-enemy-ff5b9fd8a3e8?gi=184a27ee2a08

Related issue:
#1777

Signed-off-by: Kawika Avilla <kavilla414@gmail.com>

Signed-off-by: Kawika Avilla <kavilla414@gmail.com>
Co-authored-by: Anan Zhuang <ananzh@amazon.com>
(cherry picked from commit 1a82ae3)
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

# Conflicts:
#	CHANGELOG.md

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Anan Zhuang <ananzh@amazon.com>
  • Loading branch information
3 people authored Jan 25, 2023
1 parent 2a8b3a7 commit a66d91c
Show file tree
Hide file tree
Showing 6 changed files with 38 additions and 0 deletions.
5 changes: 5 additions & 0 deletions config/opensearch_dashboards.yml
Original file line number Diff line number Diff line change
Expand Up @@ -107,6 +107,11 @@
# Logs queries sent to OpenSearch. Requires logging.verbose set to true.
#opensearch.logQueries: false

# Disables errors from the OpenSearch JS client and enables you to utilize protected words such as: 'boolean', 'proto', 'constructor'.
# within cluster. By default, OpenSearch Dashboards and the client will protect you against prototype poisoning attacks.
# WARNING: Index patterns are user-supplied data. Disabling this will place the expectation that you are handling the data safely.
#opensearch.disablePrototypePoisoningProtection: false

# Specifies the path where OpenSearch Dashboards creates the process ID file.
#pid.file: /var/run/opensearchDashboards.pid

Expand Down
18 changes: 18 additions & 0 deletions src/core/server/opensearch/client/client_config.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -184,6 +184,24 @@ describe('parseClientOptions', () => {
]
`);
});

it('`disablePrototypePoisoningProtection` option', () => {
expect(
parseClientOptions(createConfig({ disablePrototypePoisoningProtection: false }), false)
.disablePrototypePoisoningProtection
).toEqual(false);
expect(
parseClientOptions(createConfig({ disablePrototypePoisoningProtection: true }), false)
.disablePrototypePoisoningProtection
).toEqual(true);

expect(
parseClientOptions(createConfig({}), false).disablePrototypePoisoningProtection
).toBeUndefined();
expect(
parseClientOptions(createConfig({}), true).disablePrototypePoisoningProtection
).toBeUndefined();
});
});

describe('authorization', () => {
Expand Down
5 changes: 5 additions & 0 deletions src/core/server/opensearch/client/client_config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,7 @@ export type OpenSearchClientConfig = Pick<
| 'hosts'
| 'username'
| 'password'
| 'disablePrototypePoisoningProtection'
> & {
memoryCircuitBreaker?:
| OpenSearchConfig['memoryCircuitBreaker']
Expand Down Expand Up @@ -115,6 +116,10 @@ export function parseClientOptions(config: OpenSearchClientConfig, scoped: boole
);
}

if (config.disablePrototypePoisoningProtection != null) {
clientOptions.disablePrototypePoisoningProtection = config.disablePrototypePoisoningProtection;
}

return clientOptions;
}

Expand Down
1 change: 1 addition & 0 deletions src/core/server/opensearch/opensearch_config.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -72,6 +72,7 @@ test('set correct defaults', () => {
OpenSearchConfig {
"apiVersion": "7.x",
"customHeaders": Object {},
"disablePrototypePoisoningProtection": undefined,
"healthCheckDelay": "PT2.5S",
"hosts": Array [
"http://localhost:9200",
Expand Down
8 changes: 8 additions & 0 deletions src/core/server/opensearch/opensearch_config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -142,6 +142,7 @@ export const configSchema = schema.object({
}),
schema.boolean({ defaultValue: false })
),
disablePrototypePoisoningProtection: schema.maybe(schema.boolean({ defaultValue: false })),
});

const deprecations: ConfigDeprecationProvider = ({ renameFromRoot, renameFromRootWithoutMap }) => [
Expand Down Expand Up @@ -318,6 +319,12 @@ export class OpenSearchConfig {
*/
public readonly customHeaders: OpenSearchConfigType['customHeaders'];

/**
* Specifies whether the client should attempt to protect against reserved words
* or not.
*/
public readonly disablePrototypePoisoningProtection?: boolean;

constructor(rawConfig: OpenSearchConfigType) {
this.ignoreVersionMismatch = rawConfig.ignoreVersionMismatch;
this.apiVersion = rawConfig.apiVersion;
Expand All @@ -338,6 +345,7 @@ export class OpenSearchConfig {
this.username = rawConfig.username;
this.password = rawConfig.password;
this.customHeaders = rawConfig.customHeaders;
this.disablePrototypePoisoningProtection = rawConfig.disablePrototypePoisoningProtection;

const { alwaysPresentCertificate, verificationMode } = rawConfig.ssl;
const { key, keyPassphrase, certificate, certificateAuthorities } = readKeyAndCerts(rawConfig);
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,7 @@ opensearch_dashboards_vars=(
opensearch.ssl.truststore.password
opensearch.ssl.verificationMode
opensearch.username
opensearch.disablePrototypePoisoningProtection
i18n.locale
interpreter.enableInVisualize
opensearchDashboards.autocompleteTerminateAfter
Expand Down

0 comments on commit a66d91c

Please sign in to comment.