Skip to content

Cluster alert watch status page can be accesed via the URL #18191

Closed

Description

Original comment by @marius-dr:

The Edit and Status page should be unavailable to the user for the cluster alerts watches. This is true for the Edit page, but the status page can be accessed by using the direct URL to it like this:
Cluster alert watch ID: lgifRU4RTCKjZ-7391mVIQ_elasticsearch_cluster_status
URL: http://localhost:5601/app/kibana#/management/elasticsearch/watcher/watches/watch/lgifRU4RTCKjZ-7391mVIQ_elasticsearch_cluster_status/status?_g=()

You can Activate/Deactivate and even Delete the watch from that page. If you click on the Edit tab, it will show a blank page, so that one is safe from tampering.
We should should block access to this page as well and maybe add a message on it.
watch

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

No one assigned

    Labels

    Feature:WatcherTeam:Kibana ManagementDev Tools, Index Management, Upgrade Assistant, ILM, Ingest Node Pipelines, and morebugFixes for quality problems that affect the customer experience

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions