Skip to content

[9.3] Sessionless user profile retrieval (#249839)#254122

Closed
kibanamachine wants to merge 1 commit intoelastic:9.3from
kibanamachine:backport/9.3/pr-249839
Closed

[9.3] Sessionless user profile retrieval (#249839)#254122
kibanamachine wants to merge 1 commit intoelastic:9.3from
kibanamachine:backport/9.3/pr-249839

Conversation

@kibanamachine
Copy link
Copy Markdown
Contributor

Backport

This will backport the following commits from main to 9.3:

Questions ?

Please refer to the Backport tool documentation

Closes elastic#245091

## Summary

This PR enhances the user profile [getCurrent
function](https://github.com/elastic/kibana/blob/a7aca33f10bc8ccf0c4c71c458ffdc06e1e5124a/x-pack/platform/plugins/shared/security/server/user_profile/user_profile_service.ts#L191-L242)
API, and subsequently the `/internal/security/user_profile` endpoint, to
retrieve the user profile for requests authenticated via `basic` and
`apikey` authorization headers.

No breaking changes or release notes - only internal APIs are enhanced
and retain original behavior.

### Telemetry
This PR adds an OTel counter for invocations of the getCurrent function,
with optional attributes for when profile activation or API key
retrieval is required.

Note: The counter is not increased if authorization is not via session,
basic, or API key. However, in this case nothing happens and `null` is
returned.

### Tests
-
x-pack/platform/plugins/shared/security/server/user_profile/user_profile_service.test.ts
-
x-pack/platform/test/security_api_integration/tests/user_profiles/get_current.ts
-
x-pack/platform/test/cases_api_integration/security_and_spaces/config_basic.ts
-
x-pack/platform/test/cases_api_integration/security_and_spaces/config_trial.ts

The cases tests had to be updated to account for the additionally
activated user profiles. Note: I have temporarily skipped some tests
which aimed to confirm when no profile is available. I am currently
evaluating whether these tests should remain and how to implement them
given the changes.

### Checklist

Check the PR satisfies following conditions.

Reviewers should verify this PR satisfies this list as well.

- [ ] Any text added follows [EUI's writing
guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses
sentence case text and includes [i18n
support](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)
- [ ]
[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)
was added for features that require explanation or tutorials
- [x] [Unit or functional
tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)
were updated or added to match the most common scenarios
- [ ] If a plugin configuration key changed, check if it needs to be
allowlisted in the cloud and added to the [docker
list](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)
- [ ] This was checked for breaking HTTP API changes, and any breaking
changes have been approved by the breaking-change committee. The
`release_note:breaking` label should be applied in these situations.
- [ ] [Flaky Test
Runner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1) was
used on any tests changed
- [ ] The PR description includes the appropriate Release Notes section,
and the correct `release_note:*` label is applied per the
[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)
- [ ] Review the [backport
guidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)
and apply applicable `backport:*` labels.

---------

Co-authored-by: kibanamachine <42973632+kibanamachine@users.noreply.github.com>
(cherry picked from commit 6447a06)
@kibanamachine kibanamachine added the backport This PR is a backport of another PR label Feb 20, 2026
@kibanamachine kibanamachine enabled auto-merge (squash) February 20, 2026 08:31
@jeramysoucy jeramysoucy disabled auto-merge February 20, 2026 08:33
@elasticmachine
Copy link
Copy Markdown
Contributor

elasticmachine commented Feb 20, 2026

💔 Build Failed

Failed CI Steps

Test Failures

  • [job] [logs] FTR Configs #84 / cases security and spaces enabled: basic Common analytics indexes backfill task should backfill the cases index
  • [job] [logs] FTR Configs #84 / cases security and spaces enabled: basic Common analytics indexes backfill task should backfill the cases index
  • [job] [logs] FTR Configs #18 / cases security and spaces enabled: trial Common analytics indexes backfill task should backfill the cases index
  • [job] [logs] FTR Configs #18 / cases security and spaces enabled: trial Common analytics indexes backfill task should backfill the cases index

Metrics [docs]

✅ unchanged

History

cc @jeramysoucy

@jeramysoucy
Copy link
Copy Markdown
Contributor

Backport of this feature is not necessary.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport This PR is a backport of another PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants