OpenSearch/x-pack/plugin/security
Yang Wang 82553524af
Respect runas realm for ApiKey security operations (#52178) (#52932)
When user A runs as user B and performs any API key related operations,
user B's realm should always be used to associate with the API key.
Currently user A's realm is used when getting or invalidating API keys
and owner=true. The PR is to fix this bug.

resolves: #51975
2020-02-28 10:53:52 +11:00
..
cli Update BouncyCastle to 1.64 (#52185) (#52464) 2020-02-18 14:11:34 +02:00
forbidden Add an OpenID Connect authentication realm (#40674) (#41178) 2019-04-15 12:41:16 +03:00
licenses Update oauth2-oidc-sdk to 7.0 (#52489) (#52806) 2020-02-26 16:02:10 +02:00
qa [7.x] Smarter copying of the rest specs and tests (#52114) (#52798) 2020-02-26 08:13:41 -06:00
src Respect runas realm for ApiKey security operations (#52178) (#52932) 2020-02-28 10:53:52 +11:00
build.gradle Update commons-collections test dependency to 3.2.2 (#52808) (#52817) 2020-02-26 17:03:45 +02:00