diff --git a/CHANGES.txt b/CHANGES.txt
new file mode 100644
index 0000000..b06e256
--- /dev/null
+++ b/CHANGES.txt
@@ -0,0 +1,27 @@
+Apache ManifoldCF Plugin for Elastic Search change Log
+$Id: CHANGES.txt 1571169 2015-04-29  Bartlomiej Superson $
+
+======================= Release 3.0 =====================
+
+Plugin modified to work with Elasticsearch 1.5.2.
+
+======================= Release 2.0 =====================
+
+CONNECTORS-886: Add support for parent security.  This
+change requires reindexing of all content supported by this plugin.
+(Karl Wright)
+
+======================= Release 1.1 =====================
+
+Add functionality making the plugin compatible with multi-domain
+features of ManifoldCF.  Specifically, create method signatures that
+allow multiple domain/username pairs to be passed in.
+(Karl Wright)
+
+======================= Release 0.1 =====================
+
+Added the path.data parameter in the ElasticSearch server: now the data folder is created under the target folder
+(Karl Wright, Piergiorgio Lucidi)
+
+Initial commit.
+(Karl Wright)
diff --git a/DEPENDENCIES.txt b/DEPENDENCIES.txt
new file mode 100644
index 0000000..0d7e697
--- /dev/null
+++ b/DEPENDENCIES.txt
@@ -0,0 +1,11 @@
+Apache ManifoldCF Plugin for Elastic Search requires
+--------------------------------------------------
+* JRE 1.6 or above
+* mvn 2.2 or higher
+
+For building Apache ManifoldCF Plugin for Elastic Search:
+-----------------------------------------------------
+
+* Look at README.txt
+
+
diff --git a/KEYS b/KEYS
new file mode 100644
index 0000000..43f6c27
--- /dev/null
+++ b/KEYS
@@ -0,0 +1,130 @@
+(instructions copied from forrest's KEYS file)
+
+This file contains the PGP keys of various developers.
+Please don't use them for email unless you have to. Their main
+purpose is code signing.
+
+Users: pgp < KEYS
+Developers:
+        pgp -kxa <your name> and append it to this file.
+        (pgpk -ll <your name> && pgpk -xa <your name>) >> this file.
+        (gpg --list-sigs <your name>
+             && gpg --armor --export <your name>) >> this file.
+
+----------------------------------------------------------------
+pub   4096R/03824582 2010-11-19
+uid                  Karl David Wright (CODE SIGNING KEY) <kwright@apache.org>
+sig 3        03824582 2010-11-19  Karl David Wright (CODE SIGNING KEY) <kwright@apache.org>
+sub   4096R/EE82775D 2010-11-19
+sig          03824582 2010-11-19  Karl David Wright (CODE SIGNING KEY) <kwright@apache.org>
+
+-----BEGIN PGP PUBLIC KEY BLOCK-----
+Version: GnuPG v1.4.11 (MingW32)
+
+mQINBEzmR2IBEACvDjCt9SU4ma8kcrFitl6fTx3hAWJmosC1OLryVYVQ+g816NaD
+oRgKim6GcYC0wvQEHvlIpEq4xXqKIWhH4xko8wvV619uOqoK+Ca6dI7FzxnBcxQ5
+D0J59zXRikYO0qhNgZqdo+37l6AgaDMbgPUPq0XQO4KCo+XbluCZfRuL5UcbF4H5
+j4mxT3IgnMHtdzaceKP+wruh/Ak18w/6w+5GnE3QYYPGqlnBqPVTWQFjBDL+L9QD
+LWVBgduQQ3YXhDmfZGRBppzklPJeiWwBQH7mZqgjht0aoIvwLVgCgA6S9TRRcUtE
+maefHcGduKhENYgt0I3mWD41VpKLgq6kfbZYg1fCwtXd5If0KxxhsZmBlMGYCwcV
+TBzcBLhktPAFKquM/VCzu3DR8hAYQjYukOYMAAB2PGjaQlP4Rc4/vTQR8CE3oYR6
+pLgnPu8SjUcxomqKPFM1SCAx/BgUpMrWRNNO/0j9hhBlCDnHxxrTsPvMW+uqCHQp
+xNvneIuFPt7TSwcK1Luyoygtoj/3J/2zI9SCXrNJwZZzGfc26Lp4XVaGNEujwLeG
+Ik2EN2dHdcDJWOAv+szk5jgn6G9c0sb9bFCjSNI9yWjZLofTvheKIjC8EBBmB7LD
+FHLcjbCbFYGReBSWenkfcOyEq83vMrCwZ+WgVjdazZVnjCa7GntYIgOpIwARAQAB
+tDlLYXJsIERhdmlkIFdyaWdodCAoQ09ERSBTSUdOSU5HIEtFWSkgPGt3cmlnaHRA
+YXBhY2hlLm9yZz6JAjcEEwEKACEFAkzmR2ICGwMFCwkIBwMFFQoJCAsFFgIDAQAC
+HgECF4AACgkQ/R/wnAOCRYKhvg/+Nr/yGbkx3kEMhbrpco0P2+hM95J1DjihFh/5
+gDeQ5ISTENi9SQt7OBkIDGMS7FyeOXuvGpjrkqjp5PGkc/pTO3Flu/5bJAWNHQGF
+tNv51tJeGeDD8wotLvoJOLJfxZZ42JGww5TmkXqMeKUBOsBB7vqaLEuk8sm/xr0D
+R76b9b5zpcMUlQAA3rgS0Z6BGKE4X9WAmbCo7k0O+k0KNAOoB1WoUrnXKkwDwDQL
+eTOwQujLm7OiRz/nkvXx1YlpXi3u9TNcXArdOWU3HkYduSc2fcaHaj4WfzaX79CQ
+meiJBpYLglWqFaMPZPOgO9g12kMk0DsslvZZkqzcGjCB1yn5DnxgqpLLkzWmclFA
+FBPKmbxMA2iUNy1Kgn+ZhiBRYl1rz0UdTa3sthOn2paTc1IdDHUAubr8qkkfHtYp
+AaIuF+T7iqjs8J1SLhtBxqEJ8FMs9b0vSNWs+UTaXgbmYoaINMePtOgPVQfMU1Mk
+r5v/1DE99C7V0qi37AAdTEBKUKkjlU/gWVKs1dL+te/gl6b6KxyNt3oiTUFApzQP
+r5VVpNrEqWKqUVAzxif4v+iUsmQrnw2pwRCzXgQ9o8DfmqbKjKwwkWrTZMTCaNvw
+L2oT/miX1acMpmtV8Co02++gt439+Aw1ZenvQ+zuHXFglZjhHa68FJj+XtAof0Qf
+xuhLi5i5Ag0ETOZHYgEQAMHgiGeeGT7a+UApO2Wr8AM4vjTXUqnc/HpDdEOVBWMV
+Y28QGaG8MgkUhUMCNel1EHZgHF3PVmty9izrqpUOOIPoD9JBqH903+gkPAorloOA
+UzI4+4IHCSZPrhgU+akhBFfYW1SI/2noF8AUzTZnXamlLMeLaJIJDvHDIaKG6lxf
+hpPx9WGjmLP8Xf0D9WeIdmsJlKxWWBCCnWM9qZfLcrBk+cZhuDJbIPp9edPGu7DB
+qQXrmPTN9XnuRo1fUBhxxlNQ/gEsV/I4mKko+Pgs4bkRGk2b0p7/rkbuAWw9NVX1
++17vOAuP0AuHCDuT7qno4bH1m0zftDqcNyvNl8NphxCyfXljO/hCmujKqPOn1df6
+HpORDy1kKjJeiKWWeaacRwirncwT1AZuri75iUGHCer05yt/PoYRV2fYRw6TKt8g
+lPu/2UbNujGnSOkOthwFuWP6G6SF5oRg+YdkROaC00v7VTfLvCoZ9Rdh0ZhYrwmG
+sW6iJ/AsjSfGR5WtaU+ahliyTZnIUoGND3njgBKiI8E6YFzDs2Lh+nvynv/jmB/X
+1aPxieqXw1a6h/0BsQT/uqY7941XGAdWvSzg5NP6oL+sncjKd2VXVVi/P/dMbs+h
+W+lP4RBxT6elwuzUTUaiYeEmw2WL/A/wdPnQKjVr0HA6twMnzjjOs6AnGn85FlAZ
+ABEBAAGJAh8EGAEKAAkFAkzmR2ICGwwACgkQ/R/wnAOCRYLpOhAAltJjDcRTa2MI
+M45Z7WavWwVaXxbZNyIzOifR431oqyN0bz3C4KaDz2o8Rti9y0wTfS7cgzJFe0mC
+aXU01N7t/pK3IYhf+xe/f+iBZ3JASCGu+H3zLgY7qRm3q441AkPprwVqrGIemUFQ
+qTFiSbRi9/R0OzoY+T0ZILR7eu8EmIDhoBi0aWXlxzxHKikB5SqenZz/x5sbhZcy
+UdvNKe4iB4sfhAwMreBEFH6+/rlUIC8uWTb7IScBzSXj8R9hoAUXAH35T+sTs6nx
+QCW5XzO7YRQEgbaFUOSu3s5a1NVcFyhcDq9ASOOlg0JYNK9hi/UdyXUtAoXhn8WI
+1JD9d1kz6vke2YvXwkp+ntWK6dhHKPzwN2OrHSApOM7+9dLxqT/4buQWB1BXAD2S
+d8521WI9vzEW8qyI3rZhp3OLB5GUTFCw4POFIehKCDhET6gDz0MCYHVaEMBsySfT
+13/2vZd1gEh9BD9QHlrmxqo+gJqpw4q/usKMC3VNzw6appHSzQEfor2lpfx5WYy0
+iiCKmIlos2z+lIy9AarCBqOYjcWHjkYnb6QT1k/HKPuyBV7LMqoVPiQuxgZKqx01
+ZpDvtauiZqH+MMH2qe6n5sXhDQijGwXbAsFiorFj0/kWAEncJGpyI/u6q7GnHNS5
+H4n9zm2v9HW8fqSbQq3Ym8+WQ64+IK0=
+=gEd1
+-----END PGP PUBLIC KEY BLOCK-----
+pub   4096R/FE045966 2009-10-13
+      Key fingerprint = A46D 8682 A850 E44E 4FEC  20EB 8A8A 771F FE04 5966
+uid                  Grant Ingersoll (CODE SIGNING KEY) <gsingers@apache.org>
+sub   4096R/72F9E0C0 2009-10-13
+
+-----BEGIN PGP PUBLIC KEY BLOCK-----
+Version: GnuPG v1.4.7 (Darwin)
+
+mQINBErU6JEBEACsovhRB+Z8VrdTU76Qxg8u+0WiSaoilsksGgOaphWvWt0b6rA3
+PJSGuDuMJfL+lGqk+aARehiZNbNl0cGYtP4Av/fElTdSr1UlmDeFjG+7Qi7FB6KK
+vAjv4mw+XM05QRTADjpNkDfAEXGPR1GNE7lOfPvNqvAl9YMLHJOBGlVqq5ZZAPHZ
+/R6Cg7+5qHbVJKtPqSxAoPJQwg6ADwDZv9nWZfbp2VwVwBkuVxBCRBPFN+WTFmW/
+k1LSxUIeHqOG9RXo7S/DYddthE0iBzP3yKA5fs3k9zaQZNAjC92Dj/M4oDiIimqG
+DJAO7ixpQY2ug9FB4LtWkyeNRnOM1LKd3TbZNqzZt4TuhCI3C5LAfVoXRPxe4T3n
+4hvWkL/2THSKfC4u0CLGjw41rXhD86YYiIWdvxVezfESzpqZPhBrAZWfx7kB69pq
+8DxWFXCaA31S/L2I6B1ZUmpOhtxg0cDoevipne7jaqRjA7TknOC45+CrpuEkOvQO
+8rwHbtshT/JDFLPfq0ruDH21eV4QYP/JLffDGyEtoRRRr4M2DZCFkOCWIPE0l142
+5mIi0nqMSj1HK5kuwMQoNAf6vF6P6MYyGWJ8nR13CDtFOnjpOpuxZiTQhlb0cqXj
+X4yQBjFim8ztGOnHrlSh25OgeKuiCWiCIuyFGykjX21RtJ/AwiOeMr4zkwARAQAB
+tDhHcmFudCBJbmdlcnNvbGwgKENPREUgU0lHTklORyBLRVkpIDxnc2luZ2Vyc0Bh
+cGFjaGUub3JnPokCNwQTAQoAIQUCStTokQIbAwULCQgHAwUVCgkICwUWAgMBAAIe
+AQIXgAAKCRCKincf/gRZZqcfD/4+zhoLTTpTGRNutTyjPnR85aTuMUVtqYNLjEcF
+PSV7p1OPhsGd3g5iaQtwCMsbWDPRSL+Xvy4/E4D32YjUR026mzAUnICq4Z35TecT
+StIeMadgSwJ0fNvuzBB8jJfUYW6a91D9TZirEC4fRVRL1bnJvmjm0HnGLQa5uGCl
+dUMbR04YXU+5V8S6KbRtLwhiVDD/do6XKeS9PGY941sw9182mLZbIbEcQrNWf8s/
+eOnobosxg5a0WxKfSZgQfNqkkuNlsRbKwI2gSjzAl030r6pWzduvftqFdnoaOBN/
+yNM1BghAhXmb/hxjuQa0x+xan15/lY5FwDX1bdnZcEI0KHJ/FIPFgk59XJVnZYH/
+tRI6jqmxQvdliA9q6rt/ctZAYaOhmXI28eeLCmdnZKUZjiG1ORYC0tIYdOYc/nXP
+NqryDaa2OD2rMy8BM5tfQ/Om/6kavDqn/m8x0jLLuOne5Umeste3yTZ3pbJWc5GF
+izOCX0FualpLXNBWt3jCooSaj5Gx92pFgoanbtI91ouVNsC24eKOJZYibKLP5fuH
+B1sNvtPcWE3e99qOzVnolHjbDX4KzXCW+yFad714kK1vdAlDvqIt2OuEuQFggZHS
+5G5FbGjgqFUG5D0uckBmu/8lZ82YW2yhuQosa5EOMwChG1sqtsYuddbifFF78AM4
+vYnmKohGBBARCgAGBQJK1OocAAoJEMsDFRmoZ+ixVg4An0MfyRmOv0tA8/UibzyK
+KPrzo1aeAKCIV+M3L+gPT9yJ9843HxyBWL+j6bkCDQRK1OiRARAApG7lRX08hPq5
+7KRRUsK6GChneFeZZNNI35VpFQHPe8y/4ej7Ydnr37otEjIvd+14p0M+PF6igCIm
+IGp2dg57PFfoOVW+apoudAtBpWkdBSjMJQ4pCoLwyv/HSXKW6QxMZeO5OBdT4iAg
+AT36M2m/lpv5wC7g7SUJDusyFPuYtMtxAkj6TUPTFJBS4+FzhrNBoCXxILDKh0AE
+N9Sslm37tC7Le84PkiI/k0C//KqNZFQ11Cazyf0CuQKj4gLtkfBTaDenlsufAKNI
+M2pkIxtLNpx93Gcay2lVKD9Dv2i4EmQID7Vt6fZ2CP+60K7CnepLhapkfWa9Rk71
+7fqLIlXCFYdWEmuT614dnDuuuRfm12ZqT3GAx9F0elZ2yv4DrXnW1F60ASJuFnDf
+RYcbTmw2VVoDiAo2al4uoE7a2yjyv7PExB65k0Uj0n1V4PF413np3r/WLSWBxxNu
+9K8oV0KZI/UxvhMULGI23ryNTZAsoi3E44lZ0EUrJTWMRvLuewQdNpNLmlo30HNL
+VTyoIlWbzhsu4ejKVqLBs/Q9M92c/Um6FJM5owkiGBEvnRtGGWhf89RonCncwg2g
+i/rk91TTKnhGpYv3tenLjZ6qmlgMgT+KUrElqrLv02kD3xZ7+2zwhaLYWFlZN6wr
+xXlA/FDOEz3tChqG+41Vf8W26+QnC98AEQEAAYkCHwQYAQoACQUCStTokQIbDAAK
+CRCKincf/gRZZgzbEACfLTy+6afsT4wAgKYdlc+6w3bBqFnDzoG0JRIrUsVhEnjB
+xhl+RZA9XMkPvw5iAeNOWSU+SoPz8hGrv3tkGJXqfeThOAB5IVDDW8FDmm57/sl4
+2m09B+QHZ7Buw56OD90GoCSm1otkbaIUjoMTbuQxTRb1qykVHO4AgLReaeMb9jqu
+hqwxyzGzWMqVR01olgvCkSDrooYjA1ltQ84JrJhic5+zdQq1XYIv0dTPP3CcrFcy
+b6pVx+Y31hK9f0EXoNZv6Ekg6B5L7LUleB3XdCL+jI1eWlQ3DTE7+OkVcehpyygc
+JFgPVm/0KMPkHTa3Fw55YWbcrwAKGv5fWSj852pbaW/GNgDAiay0MPExEYey2cu5
+Pi8dUOmJoqcznBt9qQrrmRNWPRa1Gu9vowM9m90+jtU+Tlxo104tj8gKWVngnPhn
+v1VPKPblEwJfuqC3DQh3XWzs3AwjKLXXfwznF7slqBRT48BwdLsietnovoTsZXYg
+7ks2s/QxklWisZUxrhpZTNeA/WQKxyXwiN2sKxulwjd1PnAz5DeFQWKDNZHyHP+T
+1cqtTc96tSwb2XW3iA2uZlD4aTkrOmm3FKbauC/rFmCjkpvwpvqcIdpib4M2DgNx
+zAZ2cJnxw3f57qc9Yh5qvhDUephwOAlAy8ekc1AmX14F+mwYE3GjcqeGdEbLNw==
+=GLHu
+-----END PGP PUBLIC KEY BLOCK-----
\ No newline at end of file
diff --git a/LICENSE.txt b/LICENSE.txt
new file mode 100644
index 0000000..66a27ec
--- /dev/null
+++ b/LICENSE.txt
@@ -0,0 +1,177 @@
+                                 Apache License
+                           Version 2.0, January 2004
+                        http://www.apache.org/licenses/
+
+   TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
+
+   1. Definitions.
+
+      "License" shall mean the terms and conditions for use, reproduction,
+      and distribution as defined by Sections 1 through 9 of this document.
+
+      "Licensor" shall mean the copyright owner or entity authorized by
+      the copyright owner that is granting the License.
+
+      "Legal Entity" shall mean the union of the acting entity and all
+      other entities that control, are controlled by, or are under common
+      control with that entity. For the purposes of this definition,
+      "control" means (i) the power, direct or indirect, to cause the
+      direction or management of such entity, whether by contract or
+      otherwise, or (ii) ownership of fifty percent (50%) or more of the
+      outstanding shares, or (iii) beneficial ownership of such entity.
+
+      "You" (or "Your") shall mean an individual or Legal Entity
+      exercising permissions granted by this License.
+
+      "Source" form shall mean the preferred form for making modifications,
+      including but not limited to software source code, documentation
+      source, and configuration files.
+
+      "Object" form shall mean any form resulting from mechanical
+      transformation or translation of a Source form, including but
+      not limited to compiled object code, generated documentation,
+      and conversions to other media types.
+
+      "Work" shall mean the work of authorship, whether in Source or
+      Object form, made available under the License, as indicated by a
+      copyright notice that is included in or attached to the work
+      (an example is provided in the Appendix below).
+
+      "Derivative Works" shall mean any work, whether in Source or Object
+      form, that is based on (or derived from) the Work and for which the
+      editorial revisions, annotations, elaborations, or other modifications
+      represent, as a whole, an original work of authorship. For the purposes
+      of this License, Derivative Works shall not include works that remain
+      separable from, or merely link (or bind by name) to the interfaces of,
+      the Work and Derivative Works thereof.
+
+      "Contribution" shall mean any work of authorship, including
+      the original version of the Work and any modifications or additions
+      to that Work or Derivative Works thereof, that is intentionally
+      submitted to Licensor for inclusion in the Work by the copyright owner
+      or by an individual or Legal Entity authorized to submit on behalf of
+      the copyright owner. For the purposes of this definition, "submitted"
+      means any form of electronic, verbal, or written communication sent
+      to the Licensor or its representatives, including but not limited to
+      communication on electronic mailing lists, source code control systems,
+      and issue tracking systems that are managed by, or on behalf of, the
+      Licensor for the purpose of discussing and improving the Work, but
+      excluding communication that is conspicuously marked or otherwise
+      designated in writing by the copyright owner as "Not a Contribution."
+
+      "Contributor" shall mean Licensor and any individual or Legal Entity
+      on behalf of whom a Contribution has been received by Licensor and
+      subsequently incorporated within the Work.
+
+   2. Grant of Copyright License. Subject to the terms and conditions of
+      this License, each Contributor hereby grants to You a perpetual,
+      worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+      copyright license to reproduce, prepare Derivative Works of,
+      publicly display, publicly perform, sublicense, and distribute the
+      Work and such Derivative Works in Source or Object form.
+
+   3. Grant of Patent License. Subject to the terms and conditions of
+      this License, each Contributor hereby grants to You a perpetual,
+      worldwide, non-exclusive, no-charge, royalty-free, irrevocable
+      (except as stated in this section) patent license to make, have made,
+      use, offer to sell, sell, import, and otherwise transfer the Work,
+      where such license applies only to those patent claims licensable
+      by such Contributor that are necessarily infringed by their
+      Contribution(s) alone or by combination of their Contribution(s)
+      with the Work to which such Contribution(s) was submitted. If You
+      institute patent litigation against any entity (including a
+      cross-claim or counterclaim in a lawsuit) alleging that the Work
+      or a Contribution incorporated within the Work constitutes direct
+      or contributory patent infringement, then any patent licenses
+      granted to You under this License for that Work shall terminate
+      as of the date such litigation is filed.
+
+   4. Redistribution. You may reproduce and distribute copies of the
+      Work or Derivative Works thereof in any medium, with or without
+      modifications, and in Source or Object form, provided that You
+      meet the following conditions:
+
+      (a) You must give any other recipients of the Work or
+          Derivative Works a copy of this License; and
+
+      (b) You must cause any modified files to carry prominent notices
+          stating that You changed the files; and
+
+      (c) You must retain, in the Source form of any Derivative Works
+          that You distribute, all copyright, patent, trademark, and
+          attribution notices from the Source form of the Work,
+          excluding those notices that do not pertain to any part of
+          the Derivative Works; and
+
+      (d) If the Work includes a "NOTICE" text file as part of its
+          distribution, then any Derivative Works that You distribute must
+          include a readable copy of the attribution notices contained
+          within such NOTICE file, excluding those notices that do not
+          pertain to any part of the Derivative Works, in at least one
+          of the following places: within a NOTICE text file distributed
+          as part of the Derivative Works; within the Source form or
+          documentation, if provided along with the Derivative Works; or,
+          within a display generated by the Derivative Works, if and
+          wherever such third-party notices normally appear. The contents
+          of the NOTICE file are for informational purposes only and
+          do not modify the License. You may add Your own attribution
+          notices within Derivative Works that You distribute, alongside
+          or as an addendum to the NOTICE text from the Work, provided
+          that such additional attribution notices cannot be construed
+          as modifying the License.
+
+      You may add Your own copyright statement to Your modifications and
+      may provide additional or different license terms and conditions
+      for use, reproduction, or distribution of Your modifications, or
+      for any such Derivative Works as a whole, provided Your use,
+      reproduction, and distribution of the Work otherwise complies with
+      the conditions stated in this License.
+
+   5. Submission of Contributions. Unless You explicitly state otherwise,
+      any Contribution intentionally submitted for inclusion in the Work
+      by You to the Licensor shall be under the terms and conditions of
+      this License, without any additional terms or conditions.
+      Notwithstanding the above, nothing herein shall supersede or modify
+      the terms of any separate license agreement you may have executed
+      with Licensor regarding such Contributions.
+
+   6. Trademarks. This License does not grant permission to use the trade
+      names, trademarks, service marks, or product names of the Licensor,
+      except as required for reasonable and customary use in describing the
+      origin of the Work and reproducing the content of the NOTICE file.
+
+   7. Disclaimer of Warranty. Unless required by applicable law or
+      agreed to in writing, Licensor provides the Work (and each
+      Contributor provides its Contributions) on an "AS IS" BASIS,
+      WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
+      implied, including, without limitation, any warranties or conditions
+      of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
+      PARTICULAR PURPOSE. You are solely responsible for determining the
+      appropriateness of using or redistributing the Work and assume any
+      risks associated with Your exercise of permissions under this License.
+
+   8. Limitation of Liability. In no event and under no legal theory,
+      whether in tort (including negligence), contract, or otherwise,
+      unless required by applicable law (such as deliberate and grossly
+      negligent acts) or agreed to in writing, shall any Contributor be
+      liable to You for damages, including any direct, indirect, special,
+      incidental, or consequential damages of any character arising as a
+      result of this License or out of the use or inability to use the
+      Work (including but not limited to damages for loss of goodwill,
+      work stoppage, computer failure or malfunction, or any and all
+      other commercial damages or losses), even if such Contributor
+      has been advised of the possibility of such damages.
+
+   9. Accepting Warranty or Additional Liability. While redistributing
+      the Work or Derivative Works thereof, You may choose to offer,
+      and charge a fee for, acceptance of support, warranty, indemnity,
+      or other liability obligations and/or rights consistent with this
+      License. However, in accepting such obligations, You may act only
+      on Your own behalf and on Your sole responsibility, not on behalf
+      of any other Contributor, and only if You agree to indemnify,
+      defend, and hold each Contributor harmless for any liability
+      incurred by, or claims asserted against, such Contributor by reason
+      of your accepting any such warranty or additional liability.
+
+   END OF TERMS AND CONDITIONS
+
diff --git a/NOTICE.txt b/NOTICE.txt
new file mode 100644
index 0000000..6ff17d6
--- /dev/null
+++ b/NOTICE.txt
@@ -0,0 +1,8 @@
+Apache ManifoldCF Plugin for Elastic Search
+Original work Copyright 2010-2013 The Apache Software Foundation
+Modified work Copyright 2015 Bartlomiej Superson
+
+This product includes software developed by
+The Apache Software Foundation (http://www.apache.org/).
+
+This product includes software developed by Elasticsearch.
\ No newline at end of file
diff --git a/README.txt b/README.txt
new file mode 100644
index 0000000..2a2c86c
--- /dev/null
+++ b/README.txt
@@ -0,0 +1,114 @@
+# Licensed to the Apache Software Foundation (ASF) under one or more
+# contributor license agreements.  See the NOTICE file distributed with
+# this work for additional information regarding copyright ownership.
+# The ASF licenses this file to You under the Apache License, Version 2.0
+# (the "License"); you may not use this file except in compliance with
+# the License.  You may obtain a copy of the License at
+#
+#     http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+Compatibility
+------------
+
+This version of this component is fully functional with Apache ManifoldCF 1.6 and
+above and with Elasticsearch 1.5.2.
+
+Upgrading
+---------
+If you are replacing a version of Apache ManifoldCF Plugin for ElasticSearch that is
+older than version 2.0, you must declare two additional fields (representing parent
+acls and parent deny acls), and reindex all your documents.  Otherwise, the plugin
+will prevent you from viewing any documents.
+
+Instructions for Building Apache ManifoldCF Plugin for Elastic Search from Source
+-----------------------------------------------------------------------------
+
+1. Download the Java SE 6 JDK (Java Development Kit), or greater, from
+   http://www.oracle.com/technetwork/java/index.html.
+   You will need the JDK installed, and the %JAVA_HOME%\bin directory included
+   on your command path.  To test this, issue a "java -version" command from your
+   shell and verify that the Java version is 1.6 or greater.
+
+2. Download and install Maven 2.2.1 or later.  Maven installation and configuration
+   instructions can be found here:
+
+http://maven.apache.org/run-maven/index.html
+
+3. Build packages
+
+Execute the following command in order to build the JAR packages and install 
+them to the local repository:
+
+mvn install
+
+The JAR packages can be found in the target folder:
+
+target/elasticsearch-plugin-mcf-<VERSION>.jar
+
+... where <VERSION> is the release version
+
+4. Building distribution assemblies 
+
+Execute the following command in order to build the distribution assemblies
+
+mvn package assembly:assembly
+
+5. Fix EOL in source files
+
+Fix the archive files so the source files have the correct EOL settings:
+
+mvn antrun:run
+
+Usage
+---------
+If you want to use security filter you should pass "u" parameter to your
+HTTP query string with the name of the authenticated user.
+HTTP queries without this parameter will be processed normally.
+
+Licensing
+---------
+
+Apache ManifoldCF Plugin for Elastic Search is licensed under the
+Apache License 2.0. See the files called LICENSE.txt and NOTICE.txt
+for more information.
+
+Cryptographic Software Notice
+-----------------------------
+
+This distribution may include software that has been designed for use
+with cryptographic software. The country in which you currently reside
+may have restrictions on the import, possession, use, and/or re-export
+to another country, of encryption software. BEFORE using any encryption
+software, please check your country's laws, regulations and policies
+concerning the import, possession, or use, and re-export of encryption
+software, to see if this is permitted. See <http://www.wassenaar.org/>
+for more information.
+
+The U.S. Government Department of Commerce, Bureau of Industry and
+Security (BIS), has classified this software as Export Commodity
+Control Number (ECCN) 5D002.C.1, which includes information security
+software using or performing cryptographic functions with asymmetric
+algorithms. The form and manner of this Apache Software Foundation
+distribution makes it eligible for export under the License Exception
+ENC Technology Software Unrestricted (TSU) exception (see the BIS
+Export Administration Regulations, Section 740.13) for both object
+code and source code.
+
+The following provides more details on the included software that
+may be subject to export controls on cryptographic software:
+
+  The Apache ManifoldCF Plugin for Elastic Search does not include any
+  implementation or usage of cryptographic software at this time.
+  
+Contact
+-------
+
+  o For general information visit the main project site at
+    http://manifoldcf.apache.org
+
diff --git a/pom.xml b/pom.xml
new file mode 100644
index 0000000..2b84d87
--- /dev/null
+++ b/pom.xml
@@ -0,0 +1,295 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<!--
+ Licensed to the Apache Software Foundation (ASF) under one or more
+ contributor license agreements.  See the NOTICE file distributed with
+ this work for additional information regarding copyright ownership.
+ The ASF licenses this file to You under the Apache License, Version 2.0
+ (the "License"); you may not use this file except in compliance with
+ the License.  You may obtain a copy of the License at
+
+     http://www.apache.org/licenses/LICENSE-2.0
+
+ Unless required by applicable law or agreed to in writing, software
+ distributed under the License is distributed on an "AS IS" BASIS,
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ See the License for the specific language governing permissions and
+ limitations under the License.
+-->
+
+<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
+
+  <parent>
+    <groupId>org.apache</groupId>
+    <artifactId>apache</artifactId>
+    <version>9</version>
+    <relativePath />
+  </parent>
+
+
+  <modelVersion>4.0.0</modelVersion>
+  <groupId>org.apache.manifoldcf.elasticsearch</groupId>
+
+  <name>ManifoldCF ElasticSearch Plugin</name>
+  <artifactId>elasticsearch-plugin-mcf</artifactId>
+  <version>3.0</version>
+  <packaging>jar</packaging>
+  <description>ManifoldCF Plugin for ElasticSearch</description>
+  <inceptionYear>2015</inceptionYear>
+
+  <organization>
+    <name>The Apache Software Foundation</name>
+    <url>http://www.apache.org/</url>
+  </organization>
+
+  <!-- Move these to the parent pom, when I create a parent pom -->
+  <properties>
+    <elasticsearch.version>1.5.2</elasticsearch.version>
+    <junit.version>4.8.2</junit.version>
+    <slf4j.version>1.6.6</slf4j.version>
+    <log4j.version>1.2.16</log4j.version>
+    <httpcomponent.version>4.4.1</httpcomponent.version>
+    <jetty.version>9.2.10.v20150310</jetty.version>
+    <hamcrest.version>1.3</hamcrest.version>
+    <testng.version>6.8</testng.version>
+  </properties>
+
+  <dependencies>
+    <dependency>
+      <groupId>org.elasticsearch</groupId>
+      <artifactId>elasticsearch</artifactId>
+      <version>${elasticsearch.version}</version>
+      <scope>provided</scope>
+    </dependency>
+
+    <dependency>
+      <groupId>org.apache.httpcomponents</groupId>
+      <artifactId>httpclient</artifactId>
+      <version>${httpcomponent.version}</version>
+    </dependency>
+
+    <dependency>
+      <groupId>com.fasterxml.jackson.core</groupId>
+      <artifactId>jackson-databind</artifactId>
+      <version>2.5.3</version>
+    </dependency>
+
+    <dependency>
+      <groupId>log4j</groupId>
+      <artifactId>log4j</artifactId>
+      <version>${log4j.version}</version>
+      <scope>provided</scope>
+    </dependency>
+
+    <dependency>
+      <groupId>org.slf4j</groupId>
+      <artifactId>slf4j-api</artifactId>
+      <version>${slf4j.version}</version>
+      <scope>provided</scope>
+    </dependency>
+
+    <dependency>
+      <groupId>junit</groupId>
+      <artifactId>junit-dep</artifactId>
+      <version>${junit.version}</version>
+      <scope>test</scope>
+    </dependency>
+    
+    <dependency>
+      <groupId>org.eclipse.jetty</groupId>
+      <artifactId>jetty-server</artifactId>
+      <version>${jetty.version}</version>
+      <scope>test</scope>
+    </dependency>
+
+    <dependency>
+      <groupId>org.eclipse.jetty</groupId>
+      <artifactId>jetty-servlet</artifactId>
+      <version>${jetty.version}</version>
+      <scope>test</scope>
+    </dependency>
+
+    <dependency>
+      <groupId>org.hamcrest</groupId>
+      <artifactId>hamcrest-core</artifactId>
+      <version>${hamcrest.version}</version>
+      <scope>test</scope>
+    </dependency>
+
+    <dependency>
+      <groupId>org.hamcrest</groupId>
+      <artifactId>hamcrest-library</artifactId>
+      <version>${hamcrest.version}</version>
+      <scope>test</scope>
+    </dependency>
+
+    <dependency>
+      <groupId>org.hamcrest</groupId>
+      <artifactId>hamcrest-integration</artifactId>
+      <version>${hamcrest.version}</version>
+      <scope>test</scope>
+    </dependency>
+
+    <dependency>
+      <groupId>org.testng</groupId>
+      <artifactId>testng</artifactId>
+      <version>${testng.version}</version>
+      <scope>test</scope>
+      <exclusions>
+        <exclusion>
+          <groupId>org.hamcrest</groupId>
+          <artifactId>hamcrest-core</artifactId>
+        </exclusion>
+        <exclusion>
+          <groupId>org.hamcrest</groupId>
+          <artifactId>hamcrest-library</artifactId>
+        </exclusion>
+        <exclusion>
+          <groupId>org.hamcrest</groupId>
+          <artifactId>hamcrest-integration</artifactId>
+        </exclusion>
+        <exclusion>
+          <groupId>junit</groupId>
+          <artifactId>junit</artifactId>
+        </exclusion>
+      </exclusions>
+    </dependency>
+
+  </dependencies>
+  
+  <build>
+    <plugins>
+
+      <plugin>
+        <groupId>org.apache.maven.plugins</groupId>
+        <artifactId>maven-surefire-plugin</artifactId>
+        <configuration>
+          <argLine>-Xmx1024m</argLine>
+        </configuration>
+      </plugin>
+
+      <plugin>
+        <groupId>org.apache.maven.plugins</groupId>
+        <artifactId>maven-compiler-plugin</artifactId>
+        <version>2.3.2</version>
+        <configuration>
+          <source>1.6</source>
+          <target>1.6</target>
+        </configuration>
+      </plugin>
+
+      <plugin>
+        <artifactId>maven-jar-plugin</artifactId>
+        <configuration>
+          <archive>
+            <manifest>
+              <addClasspath>true</addClasspath>
+              <mainClass>fully.qualified.MainClass</mainClass>
+            </manifest>
+            <manifestEntries>
+              <Specification-Title>${project.name}</Specification-Title>
+              <Specification-Version>${project.version}</Specification-Version>
+              <Specification-Vendor>The Apache Software Foundation</Specification-Vendor>
+              <Implementation-Title>${project.name}</Implementation-Title>
+              <Implementation-Version>${project.version}</Implementation-Version>
+              <Implementation-Vendor>The Apache Software Foundation</Implementation-Vendor>
+              <Implementation-Vendor-Id>org.apache</Implementation-Vendor-Id>
+              <url>${project.url}</url>
+            </manifestEntries>
+          </archive>
+        </configuration>
+      </plugin>
+
+      <plugin>
+        <artifactId>maven-source-plugin</artifactId>
+        <executions>
+          <execution>
+            <id>attach-sources</id>
+            <goals>
+              <goal>jar</goal>
+            </goals>
+          </execution>
+        </executions>
+        <configuration>
+          <archive>
+            <!-- Ensure source jars have full manifest entries (note: defaults aren't suitable) -->
+            <manifestEntries>
+              <Specification-Title>${project.name}</Specification-Title>
+              <Specification-Version>${project.version}</Specification-Version>
+              <Specification-Vendor>The Apache Software Foundation</Specification-Vendor>
+              <Implementation-Title>${project.name}</Implementation-Title>
+              <Implementation-Version>${project.version}</Implementation-Version>
+              <Implementation-Vendor>The Apache Software Foundation</Implementation-Vendor>
+              <Implementation-Vendor-Id>org.apache</Implementation-Vendor-Id>
+            </manifestEntries>
+          </archive>
+        </configuration>
+      </plugin>
+
+      <plugin>
+        <artifactId>maven-assembly-plugin</artifactId>
+        <configuration>
+          <descriptors>
+            <descriptor>src/main/assembly/bin.xml</descriptor>
+            <descriptor>src/main/assembly/src.xml</descriptor>
+          </descriptors>
+          <descriptorRefs>
+            <descriptorRef>jar-with-dependencies</descriptorRef>
+          </descriptorRefs>
+          <tarLongFileMode>gnu</tarLongFileMode>
+        </configuration>
+        <executions>
+          <execution>
+            <id>make-my-jar-with-dependencies</id>
+            <phase>package</phase>
+            <goals>
+              <goal>single</goal>
+            </goals>
+          </execution>
+        </executions>
+      </plugin>
+
+      <plugin>
+        <artifactId>maven-antrun-plugin</artifactId>
+        <inherited>false</inherited>
+        <configuration>
+          <tasks>
+            <ant antfile="src/main/assembly/build.xml">
+              <property name="target" value="${project.build.directory}" />
+              <property name="package.name" value="${project.artifactId}-${project.version}-bin" />
+            </ant>
+            <ant antfile="src/main/assembly/build.xml">
+              <property name="target" value="${project.build.directory}" />
+              <property name="package.name" value="${project.artifactId}-${project.version}-src" />
+            </ant>
+          </tasks>
+        </configuration>
+      </plugin>
+
+      <plugin>
+        <artifactId>maven-resources-plugin</artifactId>
+        <version>2.5</version>
+        <configuration>
+          <encoding>UTF-8</encoding>
+        </configuration>
+      </plugin>
+
+      <plugin>
+        <artifactId>maven-clean-plugin</artifactId>
+        <version>2.4.1</version>
+      </plugin>
+
+    </plugins>
+
+    <resources>
+      <resource>
+        <directory>src/main/resources</directory>
+        <filtering>true</filtering>
+        <includes>
+          <include>**/*.properties</include>
+        </includes>
+      </resource>
+    </resources>
+
+  </build>
+
+</project>
\ No newline at end of file
diff --git a/src/main/assembly/bin.xml b/src/main/assembly/bin.xml
new file mode 100644
index 0000000..98b36ed
--- /dev/null
+++ b/src/main/assembly/bin.xml
@@ -0,0 +1,65 @@
+<!--
+   $HeadURL: http://svn.apache.org/repos/asf/httpcomponents/httpclient/trunk/src/main/assembly/bin-unix.xml $
+   $Revision: 687166 $
+   $Date: 2008-08-19 23:40:27 +0200 (Tue, 19 Aug 2008) $
+
+   ====================================================================
+   Licensed to the Apache Software Foundation (ASF) under one
+   or more contributor license agreements.  See the NOTICE file
+   distributed with this work for additional information
+   regarding copyright ownership.  The ASF licenses this file
+   to you under the Apache License, Version 2.0 (the
+   "License"); you may not use this file except in compliance
+   with the License.  You may obtain a copy of the License at
+
+     http://www.apache.org/licenses/LICENSE-2.0
+
+   Unless required by applicable law or agreed to in writing,
+   software distributed under the License is distributed on an
+   "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+   KIND, either express or implied.  See the License for the
+   specific language governing permissions and limitations
+   under the License.
+   ====================================================================
+
+   This software consists of voluntary contributions made by many
+   individuals on behalf of the Apache Software Foundation.  For more
+   information on the Apache Software Foundation, please see
+   <http://www.apache.org/>.
+ -->
+<assembly>
+    <id>bin</id>
+    <formats>
+        <format>tar.gz</format>
+        <format>zip</format>
+    </formats>
+    <moduleSets>
+      <moduleSet>
+        <binaries>
+          <outputDirectory>lib</outputDirectory>
+          <unpack>false</unpack>
+          <dependencySets>
+            <dependencySet>
+              <excludes>
+                <exclude>org.slf4j:*</exclude>
+              </excludes>
+            </dependencySet>
+          </dependencySets>
+        </binaries>
+      </moduleSet>
+    </moduleSets>
+    <fileSets>
+        <fileSet>
+          <directory></directory>
+          <outputDirectory></outputDirectory>
+          <includes>
+            <include>**/target/*.jar</include>
+            <include>README.txt</include>
+            <include>LICENSE.txt</include>
+            <include>NOTICE.txt</include>
+            <include>CHANGES.txt</include>
+            <include>DEPENDENCIES.txt</include>
+          </includes>
+        </fileSet>
+    </fileSets>
+</assembly>
diff --git a/src/main/assembly/build.xml b/src/main/assembly/build.xml
new file mode 100644
index 0000000..216625b
--- /dev/null
+++ b/src/main/assembly/build.xml
@@ -0,0 +1,65 @@
+<!-- 
+   Licensed to the Apache Software Foundation (ASF) under one
+   or more contributor license agreements.  See the NOTICE file
+   distributed with this work for additional information
+   regarding copyright ownership.  The ASF licenses this file
+   to you under the Apache License, Version 2.0 (the
+   "License"); you may not use this file except in compliance
+   with the License.  You may obtain a copy of the License at
+
+     http://www.apache.org/licenses/LICENSE-2.0
+
+   Unless required by applicable law or agreed to in writing,
+   software distributed under the License is distributed on an
+   "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+   KIND, either express or implied.  See the License for the
+   specific language governing permissions and limitations
+   under the License.
+   ====================================================================
+
+   This software consists of voluntary contributions made by many
+   individuals on behalf of the Apache Software Foundation.  For more
+   information on the Apache Software Foundation, please see
+   <http://www.apache.org />.
+ -->
+<project name="assembly-postprocess" default="fixarchives" basedir=".">
+
+  <target name="fixarchives" depends="_eolcheck,fixzip,fixtgz">
+  </target>
+
+  <target name="fixzip" unless="native.crlf">
+    <property name="tmp.dir" location="${target}/tmp"/>    
+    <property name="zip.file" location="${target}/${package.name}.zip"/>    
+    <delete dir="${tmp.dir}" />
+    <unzip src="${zip.file}" dest="${tmp.dir}"/>
+    <fixcrlf srcdir="${tmp.dir}" eol="crlf" eof="remove" fixlast="false"
+        includes="**/*.txt, **/*.xml, **/*.properties, **/*.java, **/*.html, **/*.css, **/*.apt, **/*.py, **/*.svg, **/*.xsl" />
+    <zip destfile="${zip.file}" basedir="${tmp.dir}" duplicate="preserve" />
+    <delete dir="${tmp.dir}" />
+  </target>  
+
+  <target name="fixtgz" unless="native.lf">
+    <property name="tmp.dir" location="${target}/tmp"/>    
+    <property name="gz.file" location="${target}/${package.name}.tar.gz"/>    
+    <property name="tar.file" location="${target}/${package.name}.tar"/>    
+    <delete dir="${tmp.dir}" />
+    <gunzip src="${gz.file}" dest="${tar.file}"/>
+    <untar src="${tar.file}" dest="${tmp.dir}"/>
+    <fixcrlf srcdir="${tmp.dir}" eol="lf" eof="remove" fixlast="false"
+        includes="**/*.txt, **/*.xml, **/*.properties, **/*.java, **/*.html, **/*.css, **/*.apt, **/*.py, **/*.svg, **/*.xsl" />
+    <tar destfile="${tar.file}" basedir="${tmp.dir}" longfile="gnu"/>
+    <gzip src="${tar.file}" destfile="${gz.file}"/>
+      <delete file="${tar.file}"/>
+    <delete dir="${tmp.dir}"/>
+  </target>  
+
+  <!-- Determine if the native format is CRLF or LF (or neither) -->
+  <target name="_eolcheck">
+    <condition property="native.lf">
+        <os family="unix"/>
+    </condition>
+    <condition property="native.crlf">
+        <os family="dos"/>
+    </condition>
+  </target>
+</project>
diff --git a/src/main/assembly/src.xml b/src/main/assembly/src.xml
new file mode 100644
index 0000000..c6c11c8
--- /dev/null
+++ b/src/main/assembly/src.xml
@@ -0,0 +1,46 @@
+<!-- 
+   ====================================================================
+   Licensed to the Apache Software Foundation (ASF) under one
+   or more contributor license agreements.  See the NOTICE file
+   distributed with this work for additional information
+   regarding copyright ownership.  The ASF licenses this file
+   to you under the Apache License, Version 2.0 (the
+   "License"); you may not use this file except in compliance
+   with the License.  You may obtain a copy of the License at
+
+     http://www.apache.org/licenses/LICENSE-2.0
+
+   Unless required by applicable law or agreed to in writing,
+   software distributed under the License is distributed on an
+   "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+   KIND, either express or implied.  See the License for the
+   specific language governing permissions and limitations
+   under the License.
+   ====================================================================
+
+   This software consists of voluntary contributions made by many
+   individuals on behalf of the Apache Software Foundation.  For more
+   information on the Apache Software Foundation, please see
+   <http://www.apache.org/>.
+ -->
+<assembly>
+    <id>src</id>
+    <formats>
+        <format>tar.gz</format>
+        <format>zip</format>
+    </formats>
+    <fileSets>
+        <!-- Release materials -->
+        <fileSet>
+          <directory></directory>
+          <outputDirectory></outputDirectory>
+          <excludes>
+            <exclude>**/.*</exclude>
+            <exclude>**/.*/**</exclude>
+            <exclude>**/target/**</exclude>
+            <exclude>**/lib/**</exclude>
+            <exclude>**/data/**</exclude>
+          </excludes>
+        </fileSet>
+    </fileSets>
+</assembly>
diff --git a/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerException.java b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerException.java
new file mode 100644
index 0000000..dc06718
--- /dev/null
+++ b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerException.java
@@ -0,0 +1,39 @@
+/* $Id: AuthorizerException.java 1454684 2013-03-09 11:02:31Z kwright $ */
+/* Modified to MCFAuthorizerException.java 2015-04-28 Bart Superson */
+/**
+* Licensed to the Apache Software Foundation (ASF) under one or more
+* contributor license agreements. See the NOTICE file distributed with
+* this work for additional information regarding copyright ownership.
+* The ASF licenses this file to You under the Apache License, Version 2.0
+* (the "License"); you may not use this file except in compliance with
+* the License. You may obtain a copy of the License at
+*
+* http://www.apache.org/licenses/LICENSE-2.0
+*
+* Unless required by applicable law or agreed to in writing, software
+* distributed under the License is distributed on an "AS IS" BASIS,
+* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+* See the License for the specific language governing permissions and
+* limitations under the License.
+*/
+package org.apache.manifoldcf.elasticsearch;
+
+import org.elasticsearch.ElasticsearchException;
+
+/** This class represents exceptions for authorizing ElasticSearch requests
+* to include security.  It is a singleton class whose main public method
+* is thread-safe.
+*/
+public class MCFAuthorizerException extends ElasticsearchException
+{
+  /** Constructor */
+  public MCFAuthorizerException(String message)
+  {
+    super(message);
+  }
+  
+  public MCFAuthorizerException(String message, Throwable cause)
+  {
+    super(message,cause);
+  }
+}
diff --git a/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerPlugin.java b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerPlugin.java
new file mode 100644
index 0000000..51e5cde
--- /dev/null
+++ b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerPlugin.java
@@ -0,0 +1,53 @@
+/* $Id: MCFAuthorizer.java 1571011 2014-02-23 13:46:13Z kwright $ */
+/* Modified to MCFAuthorizerPlugin.java 2015-04-28 Bart Superson */
+/**
+* Licensed to the Apache Software Foundation (ASF) under one or more
+* contributor license agreements. See the NOTICE file distributed with
+* this work for additional information regarding copyright ownership.
+* The ASF licenses this file to You under the Apache License, Version 2.0
+* (the "License"); you may not use this file except in compliance with
+* the License. You may obtain a copy of the License at
+*
+* http://www.apache.org/licenses/LICENSE-2.0
+*
+* Unless required by applicable law or agreed to in writing, software
+* distributed under the License is distributed on an "AS IS" BASIS,
+* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+* See the License for the specific language governing permissions and
+* limitations under the License.
+*/
+package org.apache.manifoldcf.elasticsearch;
+
+import org.elasticsearch.common.inject.Module;
+import org.elasticsearch.common.logging.ESLogger;
+import org.elasticsearch.common.logging.Loggers;
+
+import org.elasticsearch.plugins.AbstractPlugin;
+import org.elasticsearch.rest.RestModule;
+
+public class MCFAuthorizerPlugin extends AbstractPlugin
+{
+
+  private final ESLogger log = Loggers.getLogger(this.getClass());
+
+  public MCFAuthorizerPlugin() {
+    log.info("Starting ManifoldCF Authorizer Plugin");
+  }
+
+  @Override
+  public String name() {
+    return "elasticsearch-plugin-mcf";
+  }
+
+  @Override
+  public String description() {
+    return "Plugin to connect elasticsearch with ManifoldCF";
+  }
+
+  @Override
+  public void processModule(Module module) {
+    if (module instanceof RestModule) {
+      ((RestModule) module).addRestAction(MCFAuthorizerRestSearchAction.class);
+    }
+  }
+}
diff --git a/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerRestSearchAction.java b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerRestSearchAction.java
new file mode 100644
index 0000000..5feaf31
--- /dev/null
+++ b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerRestSearchAction.java
@@ -0,0 +1,52 @@
+/* $Id: MCFAuthorizer.java 1571011 2014-02-23 13:46:13Z kwright $ */
+/* Modified to MCFAuthorizerRestSearchAction.java 2015-04-28 Bart Superson */
+/**
+* Licensed to the Apache Software Foundation (ASF) under one or more
+* contributor license agreements. See the NOTICE file distributed with
+* this work for additional information regarding copyright ownership.
+* The ASF licenses this file to You under the Apache License, Version 2.0
+* (the "License"); you may not use this file except in compliance with
+* the License. You may obtain a copy of the License at
+*
+* http://www.apache.org/licenses/LICENSE-2.0
+*
+* Unless required by applicable law or agreed to in writing, software
+* distributed under the License is distributed on an "AS IS" BASIS,
+* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+* See the License for the specific language governing permissions and
+* limitations under the License.
+*/
+package org.apache.manifoldcf.elasticsearch;
+
+import org.elasticsearch.action.search.SearchRequest;
+import org.elasticsearch.client.Client;
+import org.elasticsearch.common.inject.Inject;
+import org.elasticsearch.common.settings.Settings;
+import org.elasticsearch.rest.*;
+import org.elasticsearch.rest.action.search.RestSearchAction;
+import org.elasticsearch.rest.action.support.RestStatusToXContentListener;
+
+ /*
+    New parseSearchRequestMCF function added in utils to parse RestRequest.
+    There are also problems with security using JavaSearchAPI, because it doesn't implements setParam function
+    to set username param, but this can be ommited using JavaScriptAPI, which allows to do that.
+    Security filter can be also applied in this class but there is a problem with proper extraSource parsing.
+    There is also a possibility to create service, inject RestController into it, register RestFilter in it, which
+    should be used only if request handled by RestSearchAction and replace query from this request with
+    the same query wrapped by security filter.
+ */
+
+public class MCFAuthorizerRestSearchAction extends RestSearchAction {
+
+  @Inject
+  public MCFAuthorizerRestSearchAction(Settings settings, final RestController restController, Client client) {
+    super(settings,restController,client);
+  }
+
+  @Override
+  public void handleRequest(RestRequest request, RestChannel channel, Client client) {
+    SearchRequest searchRequest = MCFAuthorizerUtils.parseSearchRequestMCF(request);
+    searchRequest.listenerThreaded(false);
+    client.search(searchRequest, new RestStatusToXContentListener(channel));
+  }
+}
diff --git a/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerUtils.java b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerUtils.java
new file mode 100644
index 0000000..b85695a
--- /dev/null
+++ b/src/main/java/org/apache/manifoldcf/elasticsearch/MCFAuthorizerUtils.java
@@ -0,0 +1,584 @@
+/* $Id: MCFAuthorizer.java 1571011 2014-02-23 13:46:13Z kwright $ */
+/* Modified to MCFAuthorizerUtils.java 2015-04-28 Bart Superson */
+/**
+* Licensed to the Apache Software Foundation (ASF) under one or more
+* contributor license agreements. See the NOTICE file distributed with
+* this work for additional information regarding copyright ownership.
+* The ASF licenses this file to You under the Apache License, Version 2.0
+* (the "License"); you may not use this file except in compliance with
+* the License. You may obtain a copy of the License at
+*
+* http://www.apache.org/licenses/LICENSE-2.0
+*
+* Unless required by applicable law or agreed to in writing, software
+* distributed under the License is distributed on an "AS IS" BASIS,
+* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+* See the License for the specific language governing permissions and
+* limitations under the License.
+*/
+package org.apache.manifoldcf.elasticsearch;
+
+import com.fasterxml.jackson.databind.JsonNode;
+import com.fasterxml.jackson.databind.ObjectMapper;
+import com.fasterxml.jackson.databind.node.ObjectNode;
+import org.apache.http.HttpResponse;
+import org.apache.http.client.methods.HttpGet;
+import org.apache.http.entity.ContentType;
+import org.apache.http.impl.client.CloseableHttpClient;
+import org.apache.http.impl.client.HttpClients;
+import org.apache.http.util.EntityUtils;
+import org.elasticsearch.ElasticsearchIllegalArgumentException;
+import org.elasticsearch.action.search.SearchRequest;
+import org.elasticsearch.action.support.IndicesOptions;
+import org.elasticsearch.common.Strings;
+import org.elasticsearch.common.logging.ESLogger;
+import org.elasticsearch.common.logging.Loggers;
+import org.elasticsearch.common.unit.TimeValue;
+import org.elasticsearch.index.query.*;
+import org.elasticsearch.rest.RestRequest;
+import org.elasticsearch.rest.action.search.RestSearchAction;
+import org.elasticsearch.rest.action.support.RestActions;
+import org.elasticsearch.search.Scroll;
+import org.elasticsearch.search.builder.SearchSourceBuilder;
+import org.elasticsearch.search.fetch.source.FetchSourceContext;
+import org.elasticsearch.search.sort.SortOrder;
+import org.elasticsearch.search.suggest.SuggestBuilders;
+import org.elasticsearch.search.suggest.term.TermSuggestionBuilder;
+
+import java.io.*;
+import java.net.URLEncoder;
+import java.util.ArrayList;
+import java.util.HashMap;
+import java.util.List;
+import java.util.Map;
+
+public class MCFAuthorizerUtils {
+
+  protected static String ALLOW_FIELD_PREFIX = "allow_token_";
+  protected static String DENY_FIELD_PREFIX = "deny_token_";
+
+  protected final static String AUTHORITY_BASE_URL = "http://localhost:8345/mcf-authority-service";
+  protected final static String FIELD_ALLOW_DOCUMENT = ALLOW_FIELD_PREFIX +"document";
+  protected final static String FIELD_DENY_DOCUMENT = DENY_FIELD_PREFIX +"document";
+  protected final static String FIELD_ALLOW_PARENT = ALLOW_FIELD_PREFIX +"share";
+  protected final static String FIELD_DENY_PARENT = DENY_FIELD_PREFIX +"share";
+  protected final static String FIELD_ALLOW_SHARE = ALLOW_FIELD_PREFIX +"parent";
+  protected final static String FIELD_DENY_SHARE = DENY_FIELD_PREFIX +"parent";
+
+  /** Special token for null security fields */
+  protected static final String NOSECURITY_TOKEN = "__nosecurity__";
+
+  private final static CloseableHttpClient httpClient = HttpClients.createDefault();
+
+  private static final ESLogger log = Loggers.getLogger("MCFAuthorizer");
+
+  public static SearchRequest parseSearchRequestMCF(RestRequest request) throws MCFAuthorizerException {
+    SearchRequest searchRequest;
+    //if(usernameAndDomain[0]==null) throw new MCFAuthorizerException("Username not passed.");
+    if(request.param("u")!=null) {
+      String[] authenticatedUserNamesAndDomains = request.param("u").split(",");
+      String[] indices = Strings.splitStringByCommaToArray(request.param("index"));
+      searchRequest = new SearchRequest(indices);
+      boolean isTemplateRequest = request.path().endsWith("/template");
+
+      if(request.hasContent() || request.hasParam("source")) {
+        FilterBuilder authorizationFilter = buildAuthorizationFilter(authenticatedUserNamesAndDomains);
+        FilteredQueryBuilder filteredQueryBuilder;
+
+        ObjectMapper objectMapper = new ObjectMapper();
+        ObjectNode modifiedJSON, innerJSON;
+        JsonNode requestJSON;
+
+        try {
+          requestJSON = objectMapper.readTree(RestActions.getRestContent(request).toBytes());
+          if (isTemplateRequest) {
+            modifiedJSON = (ObjectNode) requestJSON;
+            innerJSON = (ObjectNode)requestJSON.findValue("template");
+            filteredQueryBuilder = QueryBuilders.filteredQuery(QueryBuilders.wrapperQuery(innerJSON.findValue("query").toString()), authorizationFilter);
+            modifiedJSON.replace("template",innerJSON.set("query", objectMapper.readTree(filteredQueryBuilder.buildAsBytes().toBytes())));
+            searchRequest.templateSource(modifiedJSON.toString());
+          } else {
+            filteredQueryBuilder = QueryBuilders.filteredQuery(QueryBuilders.wrapperQuery(requestJSON.findValue("query").toString()), authorizationFilter);
+            modifiedJSON = (ObjectNode) requestJSON;
+            modifiedJSON.set("query", objectMapper.readTree(filteredQueryBuilder.buildAsBytes().toBytes()));
+            searchRequest.source(modifiedJSON.toString());
+          }
+        } catch (IOException e) {
+            e.printStackTrace();
+            throw new MCFAuthorizerException("JSON parser error");
+          }
+      }
+
+      searchRequest.extraSource(parseSearchSourceMCF(request));
+      searchRequest.searchType(request.param("search_type"));
+      searchRequest.queryCache(request.paramAsBoolean("query_cache", (Boolean)null));
+      String scroll = request.param("scroll");
+      if(scroll != null) {
+        searchRequest.scroll(new Scroll(TimeValue.parseTimeValue(scroll, (TimeValue)null)));
+      }
+
+      searchRequest.types(Strings.splitStringByCommaToArray(request.param("type")));
+      searchRequest.routing(request.param("routing"));
+      searchRequest.preference(request.param("preference"));
+      searchRequest.indicesOptions(IndicesOptions.fromRequest(request, searchRequest.indicesOptions()));
+    }
+    else {
+      searchRequest = RestSearchAction.parseSearchRequest(request);
+    }
+    return searchRequest;
+  }
+
+  public static SearchSourceBuilder parseSearchSourceMCF(RestRequest request) throws MCFAuthorizerException {
+    SearchSourceBuilder searchSourceBuilder = null;
+    String queryString = request.param("q");
+    if(queryString != null) {
+      String[] authenticatedUserNamesAndDomains = request.param("u").split(",");
+      FilterBuilder authorizationFilter = buildAuthorizationFilter(authenticatedUserNamesAndDomains);
+      QueryStringQueryBuilder from = QueryBuilders.queryStringQuery(queryString);
+      from.defaultField(request.param("df"));
+      from.analyzer(request.param("analyzer"));
+      from.analyzeWildcard(request.paramAsBoolean("analyze_wildcard", false));
+      from.lowercaseExpandedTerms(request.paramAsBoolean("lowercase_expanded_terms", true));
+      from.lenient(request.paramAsBoolean("lenient", (Boolean)null));
+      String size = request.param("default_operator");
+      if(size != null) {
+        if("OR".equals(size)) {
+          from.defaultOperator(QueryStringQueryBuilder.Operator.OR);
+        } else {
+          if(!"AND".equals(size)) {
+            throw new ElasticsearchIllegalArgumentException("Unsupported defaultOperator [" + size + "], can either be [OR] or [AND]");
+          }
+
+          from.defaultOperator(QueryStringQueryBuilder.Operator.AND);
+        }
+      }
+
+      if(searchSourceBuilder == null) {
+        searchSourceBuilder = new SearchSourceBuilder();
+      }
+
+      searchSourceBuilder.query(QueryBuilders.filteredQuery(from, authorizationFilter));
+    }
+    else {
+        if(!(request.hasContent() || request.hasParam("source"))){
+          if(searchSourceBuilder == null) {
+            searchSourceBuilder = new SearchSourceBuilder();
+          }
+          FilterBuilder authorizationFilter = buildAuthorizationFilter(request.param("u"));
+          searchSourceBuilder.query(QueryBuilders.filteredQuery(QueryBuilders.matchAllQuery(),authorizationFilter));
+        }
+    }
+
+    int var19 = request.paramAsInt("from", -1);
+    if(var19 != -1) {
+      if(searchSourceBuilder == null) {
+        searchSourceBuilder = new SearchSourceBuilder();
+      }
+
+      searchSourceBuilder.from(var19);
+    }
+
+    int var20 = request.paramAsInt("size", -1);
+    if(var20 != -1) {
+      if(searchSourceBuilder == null) {
+        searchSourceBuilder = new SearchSourceBuilder();
+      }
+
+      searchSourceBuilder.size(var20);
+    }
+
+    if(request.hasParam("explain")) {
+      if(searchSourceBuilder == null) {
+        searchSourceBuilder = new SearchSourceBuilder();
+      }
+
+      searchSourceBuilder.explain(request.paramAsBoolean("explain", (Boolean)null));
+    }
+
+    if(request.hasParam("version")) {
+      if(searchSourceBuilder == null) {
+        searchSourceBuilder = new SearchSourceBuilder();
+      }
+
+      searchSourceBuilder.version(request.paramAsBoolean("version", (Boolean)null));
+    }
+
+    if(request.hasParam("timeout")) {
+      if(searchSourceBuilder == null) {
+        searchSourceBuilder = new SearchSourceBuilder();
+      }
+
+      searchSourceBuilder.timeout(request.paramAsTime("timeout", (TimeValue)null));
+    }
+
+    if(request.hasParam("terminate_after")) {
+      if(searchSourceBuilder == null) {
+        searchSourceBuilder = new SearchSourceBuilder();
+      }
+
+      int sField = request.paramAsInt("terminate_after", 0);
+      if(sField < 0) {
+        throw new ElasticsearchIllegalArgumentException("terminateAfter must be > 0");
+      }
+
+      if(sField > 0) {
+        searchSourceBuilder.terminateAfter(sField);
+      }
+    }
+
+    String var21 = request.param("fields");
+    String suggestField;
+    if(var21 != null) {
+      if(searchSourceBuilder == null) {
+        searchSourceBuilder = new SearchSourceBuilder();
+      }
+
+      if(!Strings.hasText(var21)) {
+        searchSourceBuilder.noFields();
+      } else {
+        String[] fetchSourceContext = Strings.splitStringByCommaToArray(var21);
+        if(fetchSourceContext != null) {
+          String[] sSorts = fetchSourceContext;
+          int sIndicesBoost = fetchSourceContext.length;
+
+          for(int sStats = 0; sStats < sIndicesBoost; ++sStats) {
+            suggestField = sSorts[sStats];
+            searchSourceBuilder.field(suggestField);
+          }
+        }
+      }
+    }
+
+    FetchSourceContext var22 = FetchSourceContext.parseFromRestRequest(request);
+    if(var22 != null) {
+      if(searchSourceBuilder == null) {
+        searchSourceBuilder = new SearchSourceBuilder();
+      }
+
+      searchSourceBuilder.fetchSource(var22);
+    }
+
+    if(request.hasParam("track_scores")) {
+      if(searchSourceBuilder == null) {
+        searchSourceBuilder = new SearchSourceBuilder();
+      }
+
+      searchSourceBuilder.trackScores(request.paramAsBoolean("track_scores", false));
+    }
+
+    String var23 = request.param("sort");
+    int suggestText;
+    String indexName;
+    String[] var26;
+    if(var23 != null) {
+      if(searchSourceBuilder == null) {
+        searchSourceBuilder = new SearchSourceBuilder();
+      }
+
+      String[] var24 = Strings.splitStringByCommaToArray(var23);
+      var26 = var24;
+      int var27 = var24.length;
+
+      for(suggestText = 0; suggestText < var27; ++suggestText) {
+        String suggestSize = var26[suggestText];
+        int suggestMode = suggestSize.lastIndexOf(":");
+        if(suggestMode != -1) {
+          String divisor = suggestSize.substring(0, suggestMode);
+          indexName = suggestSize.substring(suggestMode + 1);
+          if("asc".equals(indexName)) {
+            searchSourceBuilder.sort(divisor, SortOrder.ASC);
+          } else if("desc".equals(indexName)) {
+            searchSourceBuilder.sort(divisor, SortOrder.DESC);
+          }
+        } else {
+          searchSourceBuilder.sort(suggestSize);
+        }
+      }
+    }
+
+    String var25 = request.param("indices_boost");
+    int var31;
+    String var32;
+    if(var25 != null) {
+      if(searchSourceBuilder == null) {
+        searchSourceBuilder = new SearchSourceBuilder();
+      }
+
+      var26 = Strings.splitStringByCommaToArray(var25);
+      String[] var29 = var26;
+      suggestText = var26.length;
+
+      for(var31 = 0; var31 < suggestText; ++var31) {
+        var32 = var29[var31];
+        int var33 = var32.indexOf(44);
+        if(var33 == -1) {
+          throw new ElasticsearchIllegalArgumentException("Illegal index boost [" + var32 + "], no \',\'");
+        }
+
+        indexName = var32.substring(0, var33);
+        String sBoost = var32.substring(var33 + 1);
+
+        try {
+          searchSourceBuilder.indexBoost(indexName, Float.parseFloat(sBoost));
+        } catch (NumberFormatException var18) {
+          throw new ElasticsearchIllegalArgumentException("Illegal index boost [" + var32 + "], boost not a float number");
+        }
+      }
+    }
+
+    String var28 = request.param("stats");
+    if(var28 != null) {
+      if(searchSourceBuilder == null) {
+        searchSourceBuilder = new SearchSourceBuilder();
+      }
+
+      searchSourceBuilder.stats(Strings.splitStringByCommaToArray(var28));
+    }
+
+    suggestField = request.param("suggest_field");
+    if(suggestField != null) {
+      String var30 = request.param("suggest_text", queryString);
+      var31 = request.paramAsInt("suggest_size", 5);
+      if(searchSourceBuilder == null) {
+        searchSourceBuilder = new SearchSourceBuilder();
+      }
+
+      var32 = request.param("suggest_mode");
+      searchSourceBuilder.suggest().addSuggestion(((TermSuggestionBuilder)((TermSuggestionBuilder)((TermSuggestionBuilder)SuggestBuilders.termSuggestion(suggestField).field(suggestField)).text(var30)).size(var31)).suggestMode(var32));
+    }
+
+    return searchSourceBuilder;
+  }
+
+  /** Main method for building a filter representing appropriate security.
+   *@param authenticatedUserNamesAndDomains is a list of user names and its domains in the form "user@domain".
+   *@return the filter builder.
+   */
+  public static FilterBuilder buildAuthorizationFilter(String[] authenticatedUserNamesAndDomains)
+          throws  MCFAuthorizerException{
+    Map<String,String> domainMap = new HashMap<String,String>();
+    for(String buffer : authenticatedUserNamesAndDomains){
+      String[] authenticatedUserNameAndDomain = buffer.split("@", 2);
+      String authenticatedUserName = authenticatedUserNameAndDomain[0];
+      String authenticatedUserDomain;
+      if(authenticatedUserNameAndDomain.length<2) authenticatedUserDomain="";
+      else authenticatedUserDomain=authenticatedUserNameAndDomain[1];
+      domainMap.put(authenticatedUserDomain, authenticatedUserName);
+    }
+    return buildAuthorizationFilter(domainMap);
+  }
+
+
+  /** Main method for building a filter representing appropriate security.
+   *@param domainMap is a map from MCF authorization domain name to user name,
+   * and describes a complete user identity.
+   *@return the filter builder.
+   */
+  public static FilterBuilder buildAuthorizationFilter(Map<String,String> domainMap)
+          throws MCFAuthorizerException
+  {
+    if (AUTHORITY_BASE_URL == null)
+      throw new IllegalStateException("Authority base URL required for finding access tokens for a user");
+
+    if (domainMap == null || domainMap.size() == 0)
+      throw new IllegalArgumentException("Cannot find user tokens for null user");
+
+    StringBuilder sb = new StringBuilder("[");
+    boolean first = true;
+    for (String domain : domainMap.keySet())
+    {
+      if (!first)
+        sb.append(",");
+      else
+        first = false;
+      sb.append(domain).append(":").append(domainMap.get(domain));
+    }
+    sb.append("]");
+    log.info("Trying to match docs for user '"+sb.toString()+"'");
+
+    return buildAuthorizationFilter(getAccessTokens(domainMap));
+  }
+
+  /** Main method for building a filter representing appropriate security.
+   *@param authenticatedUserName is a user name in the form "user@domain".
+   *@return the filter builder.
+   */
+  public static FilterBuilder buildAuthorizationFilter(String authenticatedUserName)
+          throws MCFAuthorizerException
+  {
+    return buildAuthorizationFilter(authenticatedUserName, "");
+  }
+
+  /** Main method for building a filter representing appropriate security.
+   *@param authenticatedUserName is a user name in the form "user@domain".
+   *@param authenticatedUserDomain is the corresponding MCF authorization domain.
+   *@return the filter builder.
+   */
+  public static FilterBuilder buildAuthorizationFilter(String authenticatedUserName, String authenticatedUserDomain)
+          throws MCFAuthorizerException
+  {
+    Map<String,String> domainMap = new HashMap<String,String>();
+    domainMap.put(authenticatedUserDomain, authenticatedUserName);
+    return buildAuthorizationFilter(domainMap);
+  }
+
+  /** Main method for building a filter representing appropriate security.
+   *@param userAccessTokens are a set of tokens to use to construct the filter (presumably from mod_authz_annotate, upstream)
+   *@return the wrapped query enforcing ManifoldCF security.
+   */
+  public static FilterBuilder buildAuthorizationFilter(List<String> userAccessTokens)
+          throws MCFAuthorizerException
+  {
+    BoolFilterBuilder bq = new BoolFilterBuilder();
+
+    FilterBuilder allowShareOpen = new TermFilterBuilder(FIELD_ALLOW_SHARE,NOSECURITY_TOKEN);
+    FilterBuilder denyShareOpen = new TermFilterBuilder(FIELD_DENY_SHARE,NOSECURITY_TOKEN);
+    FilterBuilder allowParentOpen = new TermFilterBuilder(FIELD_ALLOW_PARENT,NOSECURITY_TOKEN);
+    FilterBuilder denyParentOpen = new TermFilterBuilder(FIELD_DENY_PARENT,NOSECURITY_TOKEN);
+    FilterBuilder allowDocumentOpen = new TermFilterBuilder(FIELD_ALLOW_DOCUMENT,NOSECURITY_TOKEN);
+    FilterBuilder denyDocumentOpen = new TermFilterBuilder(FIELD_DENY_DOCUMENT,NOSECURITY_TOKEN);
+
+    if (userAccessTokens == null || userAccessTokens.size() == 0)
+    {
+      // Only open documents can be included.
+      // That query is:
+      // (FIELD_ALLOW_SHARE is empty AND FIELD_DENY_SHARE is empty AND FIELD_ALLOW_DOCUMENT is empty AND FIELD_DENY_DOCUMENT is empty)
+      // We're trying to map to:  -(FIELD_ALLOW_SHARE:*) , which should be pretty efficient in Solr because it is negated.  If this turns out not to be so, then we should
+      // have the SolrConnector inject a special token into these fields when they otherwise would be empty, and we can trivially match on that token.
+      bq.must(allowShareOpen);
+      bq.must(denyShareOpen);
+      bq.must(allowParentOpen);
+      bq.must(denyParentOpen);
+      bq.must(allowDocumentOpen);
+      bq.must(denyDocumentOpen);
+    }
+    else
+    {
+      // Extend the query appropriately for each user access token.
+      bq.must(calculateCompleteSubquery(FIELD_ALLOW_SHARE, FIELD_DENY_SHARE,allowShareOpen,denyShareOpen,userAccessTokens));
+      bq.must(calculateCompleteSubquery(FIELD_ALLOW_DOCUMENT, FIELD_DENY_DOCUMENT,allowDocumentOpen,denyDocumentOpen,userAccessTokens));
+      bq.must(calculateCompleteSubquery(FIELD_ALLOW_PARENT, FIELD_DENY_PARENT,allowParentOpen,denyParentOpen,userAccessTokens));
+    }
+
+    return bq;
+  }
+
+  /** Calculate a complete subclause, representing something like:
+   * ((FIELD_ALLOW_SHARE is empty AND FIELD_DENY_SHARE is empty) OR FIELD_ALLOW_SHARE HAS token1 OR FIELD_ALLOW_SHARE HAS token2 ...)
+   *     AND FIELD_DENY_SHARE DOESN'T_HAVE token1 AND FIELD_DENY_SHARE DOESN'T_HAVE token2 ...
+   */
+  private static FilterBuilder calculateCompleteSubquery(String allowField, String denyField, FilterBuilder allowOpen, FilterBuilder denyOpen, List<String> userAccessTokens)
+  {
+    BoolFilterBuilder bq = new BoolFilterBuilder();
+    // No ES equivalent - hope this is done right inside
+    //bq.setMaxClauseCount(1000000);
+
+    // Add the empty-acl case
+    BoolFilterBuilder subUnprotectedClause = new BoolFilterBuilder();
+    subUnprotectedClause.must(allowOpen);
+    subUnprotectedClause.must(denyOpen);
+    bq.should(subUnprotectedClause);
+    for (String accessToken : userAccessTokens)
+    {
+      bq.should(new TermFilterBuilder(allowField,accessToken));
+      bq.mustNot(new TermFilterBuilder(denyField,accessToken));
+    }
+    return bq;
+  }
+
+  /** Get access tokens given a username */
+  protected static List<String> getAccessTokens(Map<String,String> domainMap)
+          throws MCFAuthorizerException
+  {
+    try
+    {
+      StringBuilder urlBuffer = new StringBuilder(AUTHORITY_BASE_URL);
+      urlBuffer.append("/UserACLs");
+      int i = 0;
+      for (String domain : domainMap.keySet())
+      {
+        if (i == 0)
+          urlBuffer.append("?");
+        else
+          urlBuffer.append("&");
+        // For backwards compatibility, handle the singleton case specially
+        if (domainMap.size() == 1 && domain.length() == 0)
+        {
+          urlBuffer.append("username=").append(URLEncoder.encode(domainMap.get(domain),"utf-8"));
+        }
+        else
+        {
+          urlBuffer.append("username_").append(Integer.toString(i)).append("=").append(URLEncoder.encode(domainMap.get(domain),"utf-8")).append("&")
+                  .append("domain_").append(Integer.toString(i)).append("=").append(URLEncoder.encode(domain,"utf-8"));
+        }
+        i++;
+      }
+      String theURL = urlBuffer.toString();
+      HttpGet method = new HttpGet(theURL);
+      try
+      {
+        HttpResponse httpResponse = httpClient.execute(method);
+        int rval = httpResponse.getStatusLine().getStatusCode();
+        if (rval != 200)
+        {
+          String response = EntityUtils.toString(httpResponse.getEntity(),"utf-8");
+          throw new MCFAuthorizerException("Couldn't fetch user's access tokens from ManifoldCF authority service: "+Integer.toString(rval)+"; "+response);
+        }
+        InputStream is = httpResponse.getEntity().getContent();
+        try
+        {
+          String charSet = ContentType.getOrDefault(httpResponse.getEntity()).getCharset().toString();
+          if (charSet == null)
+            charSet = "utf-8";
+          Reader r = new InputStreamReader(is,charSet);
+          try
+          {
+            BufferedReader br = new BufferedReader(r);
+            try
+            {
+              // Read the tokens, one line at a time.  If any authorities are down, we have no current way to note that, but someday we will.
+              List<String> tokenList = new ArrayList<String>();
+              while (true)
+              {
+                String line = br.readLine();
+                if (line == null)
+                  break;
+                if (line.startsWith("TOKEN:"))
+                {
+                  tokenList.add(line.substring("TOKEN:".length()));
+                  log.info(line);
+                }
+                else {
+                  // It probably says something about the state of the authority(s) involved, so log it
+                  log.info("Saw authority response "+line);
+                }
+              }
+              return tokenList;
+            }
+            finally
+            {
+              br.close();
+            }
+          }
+          finally
+          {
+            r.close();
+          }
+        }
+        finally
+        {
+          is.close();
+        }
+      }
+      finally
+      {
+        method.abort();
+      }
+    }
+    catch (IOException e)
+    {
+      throw new MCFAuthorizerException("IO exception: "+e.getMessage(),e);
+    }
+  }
+
+}
diff --git a/src/main/resources/es-plugin.properties b/src/main/resources/es-plugin.properties
new file mode 100644
index 0000000..bb023dd
--- /dev/null
+++ b/src/main/resources/es-plugin.properties
@@ -0,0 +1,2 @@
+plugin=${project.groupId}.MCFAuthorizerPlugin
+version=${project.version}
\ No newline at end of file
