Skip to content

Add notifications_send_access reserved role - #6602

Open
eirsep wants to merge 1 commit into
opensearch-project:mainfrom
eirsep:notifications-send-access-role
Open

eirsep wants to merge 1 commit into
opensearch-project:mainfrom
eirsep:notifications-send-access-role

Conversation

@eirsep

@eirsep eirsep commented Oct 5, 2026

Copy link
Copy Markdown
Member

Description

Adds a reserved role, notifications_send_access, for callers that send messages through existing Notifications channels but must not manage them.

  • Category: New feature
  • Why these changes are required? Notifications is adding a REST API to send a message to existing channels ([FEATURE] REST API to send a message to existing notification channels notifications#1279), authorized by cluster:admin/opensearch/notifications/feature/send. Today the only reserved role that grants it is notifications_full_access, which also grants channel create, update and delete.
  • What is the old behavior before changes and new behavior after changes? Sending required notifications_full_access. notifications_send_access now grants feature/send, channels/get and features, with no configs/* action.
Role Permissions
notifications_send_access notifications/channels/get, notifications/feature/send, notifications/features

Issues Resolved

Related: opensearch-project/notifications#1279

Is this a backport? No.

Do these changes introduce new permission(s) to be displayed in the static dropdown on the front-end? No. cluster:admin/opensearch/notifications/feature/send is an existing action.

Testing

node check-permissions-order.js config/roles.yml passes. The role's permission set is exercised by the security-enabled integration tests in opensearch-project/notifications.

Check List

  • New functionality includes testing
  • New functionality has been documented
  • New Roles/Permissions have a corresponding security dashboards plugin PR
  • API changes companion pull request created
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Adds a reserved role that can send messages through existing
Notifications channels without being able to create, update or delete
them: cluster:admin/opensearch/notifications/feature/send, plus
channels/get and features so the caller can choose a channel.

Related: opensearch-project/notifications#1279
Signed-off-by: Surya Sashank Nistala <snistala@amazon.com>
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

🧪 No relevant tests
🔒 No security concerns identified
✅ No TODO sections
🔀 No multiple PR themes
⚡ No major issues detected

Comment thread config/roles.yml
reserved: true
cluster_permissions:
- 'cluster:admin/opensearch/notifications/channels/get'
- 'cluster:admin/opensearch/notifications/feature/send'

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why is this called feature/send opposed to channel/send?

Comment thread config/roles.yml
- 'cluster:admin/opensearch/notifications/features'

# Allows users to send messages through existing Notifications channels
notifications_send_access:

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wdyt about simplifying this to notifications_send?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants