Skip to content

fix: remove inert opensearch_security.cookie.ttl setting - #1534

Merged
asteriscos merged 1 commit into
5.0.0from
fix/6025-remove-cookie-ttl-config
Aug 28, 2026
Merged

fix: remove inert opensearch_security.cookie.ttl setting#1534
asteriscos merged 1 commit into
5.0.0from
fix/6025-remove-cookie-ttl-config

Conversation

@Desvelao

Copy link
Copy Markdown
Member

Description

opensearch_security.cookie.ttl is shipped in the default dashboard configuration and reads as a hard cookie lifetime, but the security plugin (wazuh-security-dashboards-plugin) never consumes it — only opensearch_security.session.ttl has any effect on session/cookie expiry. Verified by grepping the plugin's server code for every consumer of the cookie config block: .secure, .name, .password, .isSameSite, and .domain are all read; .ttl is not. Shipping a setting that silently does nothing misleads operators who set it expecting it to bound the cookie's lifetime.

Proposed Changes

  • Remove the inert opensearch_security.cookie.ttl: 900000 line from:
    • config/opensearch_dashboards.prod.yml
    • docker/config/opensearch_dashboards.dev.security.yml
  • opensearch_security.session.ttl (already present in both files) remains the only setting governing session/cookie expiry — no behavior change.

Results and Evidence

No functional change: cookie.ttl had no effect before this change, so dashboard session expiry behavior is identical before/after. This only removes a misleading, unused config line.

Artifacts Affected

  • Default configuration files: config/opensearch_dashboards.prod.yml, docker/config/opensearch_dashboards.dev.security.yml

Configuration Changes

  • Removes opensearch_security.cookie.ttl from the shipped default config. Operators who had explicitly set this value in their own config are unaffected functionally (it never did anything); they should rely on opensearch_security.session.ttl instead.

Documentation Updates

N/A

Tests Introduced

N/A (config-only change)

Review Checklist

  • Code changes reviewed
  • Relevant evidence provided
  • Tests cover the new functionality
  • Configuration changes documented
  • Developer documentation reflects the changes
  • Meets requirements and/or definition of done
  • No unresolved dependencies with other issues
  • PR is linked to the relevant issue(s)
  • Correct labels applied (e.g., no-changelog)
  • ...

The dashboard config declares opensearch_security.cookie.ttl, but the
security plugin never reads it: only opensearch_security.session.ttl
governs session/cookie expiry. Shipping the setting misleads operators
into believing it bounds the cookie lifetime.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
@Desvelao Desvelao self-assigned this Aug 27, 2026
@Desvelao
Desvelao marked this pull request as ready for review August 27, 2026 15:05

@rodrigofez rodrigofez left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 CR
🟢 Test (no impact)

image

@asteriscos
asteriscos merged commit 800654c into 5.0.0 Aug 28, 2026
44 checks passed
@asteriscos
asteriscos deleted the fix/6025-remove-cookie-ttl-config branch August 28, 2026 18:27
yenienserrano added a commit that referenced this pull request Aug 31, 2026
* Report skipped bumps in the repository bumper workflow (#1492)

Improve repository bumper error handling

* Recalculate flyout position when the sidecar is opened (#1503)

* Adapt flyout position in relation to the sidecar

* Add changelog

* Change resizable button emphasis style from :focus to :active (#1508)

* fix(sidecar): change resizable button emphasis style from :focus to :active

Update the .sidecar-resizableButton CSS to emphasize the "grab" icon
on :active instead of :focus, matching the intended interaction
feedback when dragging the resizer.

Closes wazuh/wazuh-dashboard-plugins#8989

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* fix(sidecar): remove leftover native focus outline on resizable button

The resizable button programmatically calls .focus() on every click,
so after removing the custom :focus emphasis in favor of :active, the
browser's default focus outline was left showing as an unstyled
colored border until focus moved elsewhere. Suppress it for
mouse/touch interaction while keeping it for keyboard users via
:focus-visible.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* fix(sidecar): opt out resizable button from the global focus-ring animation

The resizable button programmatically calls .focus() on every click,
which triggered OSD's global brute-force focus-ring animation
(:focus:not([class^="eui"]):not(.osd-resetFocusState) in _base.scss)
since the button isn't an EUI component. That showed as a lingering
colored border after dragging, independent from the button's own
:active styling. Opt out via the "osd-resetFocusState" class, which is
the mechanism _base.scss already documents for components with
hand-crafted focus states, instead of fighting the rule's
!important/specificity locally. Supersedes the previous outline:none
attempt, which didn't target the actual animation.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* feat(sidecar): allow configuring the resizable button className

Add an optional className prop to ResizableButton, and forward it from
a new classNameButton option on OverlaySidecarOpenOptions/Sidecar, so
callers of overlays.sidecar.open() can style/opt-out the resizer
button (e.g. pass "osd-resetFocusState" to drop the global focus-ring
animation) without hardcoding it in the component.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude <noreply@anthropic.com>

* Change top bar health-check icon (#1505)

* feat: update health check indicator

* Change top bar health-check icon to a pulse shown only when attention is needed

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>

* fix(core): use kebab-case for sidecar docked-mode CSS variable

Rename --osdSidecarSize to --osd-sidecar-size and switch attribute
selectors to double quotes to satisfy the repo's stylelint rules
(custom-property-pattern, string-quotes), registering sidecar.scss
in the global selectors allowlist for its .euiFlyout references.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* chore: use constant

* Rework health-check popover

* Rework health-check popover

* List failing health checks in the nav-button popover

Show the enabled non-green checks as an EuiHealth list in the health-check
popover, labelled by the check name and with the error surfaced in a tooltip.
Use the shared mapTaskStatusToHealthColor helper and TASK.RUN_RESULT constants
instead of magic strings.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>

* Fix popover closes when clicking inside

* Close popover after navigating to the health check

---------

Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>

* Bump 5.0.0 branch (#1513)

feat: bump 5.0.0

* Fix RPM changelog entry order causing build failure (#1516)

Fix RPM changelog entry order for 5.0.0

The 5.0.0 changelog entry was placed out of descending chronological
order, causing rpmbuild to fail while parsing %changelog.

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* Merge 4.14.9 into 5.0.0 (#1517)

Remove unnecessary debhelper install-time dependency (#1484)

fix: remove unnecessary debhelper install-time dependency

debhelper is only required to build the .deb package (declared under
Build-Depends in dev-tools/build-packages/deb/debian/control), not to
install a pre-built one. Remove it from the apt-get install steps used
to test package install/upgrade.

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>

* Merge 4.14.9 into 5.0.0 (#1537)

Merge 4.14.9 into 5.0.0: no changes (verified 2026-08-28)

* fix: remove inert opensearch_security.cookie.ttl setting (#1534)

The dashboard config declares opensearch_security.cookie.ttl, but the
security plugin never reads it: only opensearch_security.session.ttl
governs session/cookie expiry. Shipping the setting misleads operators
into believing it bounds the cookie lifetime.

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude <noreply@anthropic.com>

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Rodrigo López <37187963+rodrigofez@users.noreply.github.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Wazuh CI <22834044+wazuhci@users.noreply.github.com>
yenienserrano added a commit that referenced this pull request Aug 31, 2026
* Merge 5.0.0 into 5.0.1 (#1518)

* Report skipped bumps in the repository bumper workflow (#1492)

Improve repository bumper error handling

* Recalculate flyout position when the sidecar is opened (#1503)

* Adapt flyout position in relation to the sidecar

* Add changelog

* Change resizable button emphasis style from :focus to :active (#1508)

* fix(sidecar): change resizable button emphasis style from :focus to :active

Update the .sidecar-resizableButton CSS to emphasize the "grab" icon
on :active instead of :focus, matching the intended interaction
feedback when dragging the resizer.

Closes wazuh/wazuh-dashboard-plugins#8989

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* fix(sidecar): remove leftover native focus outline on resizable button

The resizable button programmatically calls .focus() on every click,
so after removing the custom :focus emphasis in favor of :active, the
browser's default focus outline was left showing as an unstyled
colored border until focus moved elsewhere. Suppress it for
mouse/touch interaction while keeping it for keyboard users via
:focus-visible.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* fix(sidecar): opt out resizable button from the global focus-ring animation

The resizable button programmatically calls .focus() on every click,
which triggered OSD's global brute-force focus-ring animation
(:focus:not([class^="eui"]):not(.osd-resetFocusState) in _base.scss)
since the button isn't an EUI component. That showed as a lingering
colored border after dragging, independent from the button's own
:active styling. Opt out via the "osd-resetFocusState" class, which is
the mechanism _base.scss already documents for components with
hand-crafted focus states, instead of fighting the rule's
!important/specificity locally. Supersedes the previous outline:none
attempt, which didn't target the actual animation.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* feat(sidecar): allow configuring the resizable button className

Add an optional className prop to ResizableButton, and forward it from
a new classNameButton option on OverlaySidecarOpenOptions/Sidecar, so
callers of overlays.sidecar.open() can style/opt-out the resizer
button (e.g. pass "osd-resetFocusState" to drop the global focus-ring
animation) without hardcoding it in the component.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude <noreply@anthropic.com>

* Change top bar health-check icon (#1505)

* feat: update health check indicator

* Change top bar health-check icon to a pulse shown only when attention is needed

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>

* fix(core): use kebab-case for sidecar docked-mode CSS variable

Rename --osdSidecarSize to --osd-sidecar-size and switch attribute
selectors to double quotes to satisfy the repo's stylelint rules
(custom-property-pattern, string-quotes), registering sidecar.scss
in the global selectors allowlist for its .euiFlyout references.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* chore: use constant

* Rework health-check popover

* Rework health-check popover

* List failing health checks in the nav-button popover

Show the enabled non-green checks as an EuiHealth list in the health-check
popover, labelled by the check name and with the error surfaced in a tooltip.
Use the shared mapTaskStatusToHealthColor helper and TASK.RUN_RESULT constants
instead of magic strings.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>

* Fix popover closes when clicking inside

* Close popover after navigating to the health check

---------

Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>

* Bump 5.0.0 branch (#1513)

feat: bump 5.0.0

* Fix RPM changelog entry order causing build failure (#1516)

Fix RPM changelog entry order for 5.0.0

The 5.0.0 changelog entry was placed out of descending chronological
order, causing rpmbuild to fail while parsing %changelog.

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* Merge 4.14.9 into 5.0.0 (#1517)

Remove unnecessary debhelper install-time dependency (#1484)

fix: remove unnecessary debhelper install-time dependency

debhelper is only required to build the .deb package (declared under
Build-Depends in dev-tools/build-packages/deb/debian/control), not to
install a pre-built one. Remove it from the apt-get install steps used
to test package install/upgrade.

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Rodrigo López <37187963+rodrigofez@users.noreply.github.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Wazuh CI <22834044+wazuhci@users.noreply.github.com>

* Merge 5.0.0 into 5.0.1 (#1541)

* Report skipped bumps in the repository bumper workflow (#1492)

Improve repository bumper error handling

* Recalculate flyout position when the sidecar is opened (#1503)

* Adapt flyout position in relation to the sidecar

* Add changelog

* Change resizable button emphasis style from :focus to :active (#1508)

* fix(sidecar): change resizable button emphasis style from :focus to :active

Update the .sidecar-resizableButton CSS to emphasize the "grab" icon
on :active instead of :focus, matching the intended interaction
feedback when dragging the resizer.

Closes wazuh/wazuh-dashboard-plugins#8989

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* fix(sidecar): remove leftover native focus outline on resizable button

The resizable button programmatically calls .focus() on every click,
so after removing the custom :focus emphasis in favor of :active, the
browser's default focus outline was left showing as an unstyled
colored border until focus moved elsewhere. Suppress it for
mouse/touch interaction while keeping it for keyboard users via
:focus-visible.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* fix(sidecar): opt out resizable button from the global focus-ring animation

The resizable button programmatically calls .focus() on every click,
which triggered OSD's global brute-force focus-ring animation
(:focus:not([class^="eui"]):not(.osd-resetFocusState) in _base.scss)
since the button isn't an EUI component. That showed as a lingering
colored border after dragging, independent from the button's own
:active styling. Opt out via the "osd-resetFocusState" class, which is
the mechanism _base.scss already documents for components with
hand-crafted focus states, instead of fighting the rule's
!important/specificity locally. Supersedes the previous outline:none
attempt, which didn't target the actual animation.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* feat(sidecar): allow configuring the resizable button className

Add an optional className prop to ResizableButton, and forward it from
a new classNameButton option on OverlaySidecarOpenOptions/Sidecar, so
callers of overlays.sidecar.open() can style/opt-out the resizer
button (e.g. pass "osd-resetFocusState" to drop the global focus-ring
animation) without hardcoding it in the component.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude <noreply@anthropic.com>

* Change top bar health-check icon (#1505)

* feat: update health check indicator

* Change top bar health-check icon to a pulse shown only when attention is needed

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>

* fix(core): use kebab-case for sidecar docked-mode CSS variable

Rename --osdSidecarSize to --osd-sidecar-size and switch attribute
selectors to double quotes to satisfy the repo's stylelint rules
(custom-property-pattern, string-quotes), registering sidecar.scss
in the global selectors allowlist for its .euiFlyout references.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* chore: use constant

* Rework health-check popover

* Rework health-check popover

* List failing health checks in the nav-button popover

Show the enabled non-green checks as an EuiHealth list in the health-check
popover, labelled by the check name and with the error surfaced in a tooltip.
Use the shared mapTaskStatusToHealthColor helper and TASK.RUN_RESULT constants
instead of magic strings.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>

* Fix popover closes when clicking inside

* Close popover after navigating to the health check

---------

Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>

* Bump 5.0.0 branch (#1513)

feat: bump 5.0.0

* Fix RPM changelog entry order causing build failure (#1516)

Fix RPM changelog entry order for 5.0.0

The 5.0.0 changelog entry was placed out of descending chronological
order, causing rpmbuild to fail while parsing %changelog.

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* Merge 4.14.9 into 5.0.0 (#1517)

Remove unnecessary debhelper install-time dependency (#1484)

fix: remove unnecessary debhelper install-time dependency

debhelper is only required to build the .deb package (declared under
Build-Depends in dev-tools/build-packages/deb/debian/control), not to
install a pre-built one. Remove it from the apt-get install steps used
to test package install/upgrade.

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>

* Merge 4.14.9 into 5.0.0 (#1537)

Merge 4.14.9 into 5.0.0: no changes (verified 2026-08-28)

* fix: remove inert opensearch_security.cookie.ttl setting (#1534)

The dashboard config declares opensearch_security.cookie.ttl, but the
security plugin never reads it: only opensearch_security.session.ttl
governs session/cookie expiry. Shipping the setting misleads operators
into believing it bounds the cookie lifetime.

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude <noreply@anthropic.com>

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Rodrigo López <37187963+rodrigofez@users.noreply.github.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Wazuh CI <22834044+wazuhci@users.noreply.github.com>

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Rodrigo López <37187963+rodrigofez@users.noreply.github.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Wazuh CI <22834044+wazuhci@users.noreply.github.com>
yenienserrano added a commit that referenced this pull request Sep 4, 2026
* Report skipped bumps in the repository bumper workflow (#1492)

Improve repository bumper error handling

* Recalculate flyout position when the sidecar is opened (#1503)

* Adapt flyout position in relation to the sidecar

* Add changelog

* Change resizable button emphasis style from :focus to :active (#1508)

* fix(sidecar): change resizable button emphasis style from :focus to :active

Update the .sidecar-resizableButton CSS to emphasize the "grab" icon
on :active instead of :focus, matching the intended interaction
feedback when dragging the resizer.

Closes wazuh/wazuh-dashboard-plugins#8989

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* fix(sidecar): remove leftover native focus outline on resizable button

The resizable button programmatically calls .focus() on every click,
so after removing the custom :focus emphasis in favor of :active, the
browser's default focus outline was left showing as an unstyled
colored border until focus moved elsewhere. Suppress it for
mouse/touch interaction while keeping it for keyboard users via
:focus-visible.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* fix(sidecar): opt out resizable button from the global focus-ring animation

The resizable button programmatically calls .focus() on every click,
which triggered OSD's global brute-force focus-ring animation
(:focus:not([class^="eui"]):not(.osd-resetFocusState) in _base.scss)
since the button isn't an EUI component. That showed as a lingering
colored border after dragging, independent from the button's own
:active styling. Opt out via the "osd-resetFocusState" class, which is
the mechanism _base.scss already documents for components with
hand-crafted focus states, instead of fighting the rule's
!important/specificity locally. Supersedes the previous outline:none
attempt, which didn't target the actual animation.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* feat(sidecar): allow configuring the resizable button className

Add an optional className prop to ResizableButton, and forward it from
a new classNameButton option on OverlaySidecarOpenOptions/Sidecar, so
callers of overlays.sidecar.open() can style/opt-out the resizer
button (e.g. pass "osd-resetFocusState" to drop the global focus-ring
animation) without hardcoding it in the component.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude <noreply@anthropic.com>

* Change top bar health-check icon (#1505)

* feat: update health check indicator

* Change top bar health-check icon to a pulse shown only when attention is needed

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>

* fix(core): use kebab-case for sidecar docked-mode CSS variable

Rename --osdSidecarSize to --osd-sidecar-size and switch attribute
selectors to double quotes to satisfy the repo's stylelint rules
(custom-property-pattern, string-quotes), registering sidecar.scss
in the global selectors allowlist for its .euiFlyout references.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* chore: use constant

* Rework health-check popover

* Rework health-check popover

* List failing health checks in the nav-button popover

Show the enabled non-green checks as an EuiHealth list in the health-check
popover, labelled by the check name and with the error surfaced in a tooltip.
Use the shared mapTaskStatusToHealthColor helper and TASK.RUN_RESULT constants
instead of magic strings.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>

* Fix popover closes when clicking inside

* Close popover after navigating to the health check

---------

Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>

* Bump 5.0.0 branch (#1513)

feat: bump 5.0.0

* Fix RPM changelog entry order causing build failure (#1516)

Fix RPM changelog entry order for 5.0.0

The 5.0.0 changelog entry was placed out of descending chronological
order, causing rpmbuild to fail while parsing %changelog.

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* Merge 4.14.9 into 5.0.0 (#1517)

Remove unnecessary debhelper install-time dependency (#1484)

fix: remove unnecessary debhelper install-time dependency

debhelper is only required to build the .deb package (declared under
Build-Depends in dev-tools/build-packages/deb/debian/control), not to
install a pre-built one. Remove it from the apt-get install steps used
to test package install/upgrade.

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>

* Merge 4.14.9 into 5.0.0 (#1537)

Merge 4.14.9 into 5.0.0: no changes (verified 2026-08-28)

* fix: remove inert opensearch_security.cookie.ttl setting (#1534)

The dashboard config declares opensearch_security.cookie.ttl, but the
security plugin never reads it: only opensearch_security.session.ttl
governs session/cookie expiry. Shipping the setting misleads operators
into believing it bounds the cookie lifetime.

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude <noreply@anthropic.com>

* Bump 5.0.0 branch (#1545)

feat: bump 5.0.0

* Revert bump 5.0.0 branch (#1546)

feat: revert 5.0.0 references

* Fix changelog not in descending chronological order (#1548)

* fix: keep RPM changelog entries in descending date order on re-bump (#1549)

Re-bumping an existing version updated its date in place instead of
repositioning it, so a newer date could end up below older entries and
rpmbuild rejected the spec (%changelog not in descending chronological
order). The entry is now removed and reinserted at the position
matching its date.

Also fixes date/sed portability on macOS (BSD date/sed vs GNU), and
makes an invalid date abort the script instead of writing the error
text into the changelog.

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* Bump 5.0.0 branch (#1551)

feat: bump 5.0.0

* Review the 5.0.0 changelog (#1556)

* docs(changelog): review the 5.0.0 entries

Removed the open redirect fix entry (#1285) and the pre install script
check entry (#1328, #1365).

Reordered the sections to Added, Changed, Removed, Fixed, and qualified
the two wazuh-dashboard-plugins references so they no longer read as
wazuh-dashboard issues.

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* docs(changelog): reference issues instead of pull requests

Each entry now links the issue the pull request closed, so the reference
carries the description and the discussion instead of just the diff.

Where an entry listed several references that resolve the same issue, it
collapses to that one; where they resolve different issues, the entry
keeps the main one and the rest are attached to it as sub-issues on
GitHub, following the shape of wazuh-dashboard-plugins#8789.

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* docs(changelog): merge the health check service and app entries

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>

* docs(changelog): point the health check entry at its parent issue

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>

---------

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Merge 4.14.9 into 5.0.0 (#1563)

Merge 4.14.8 into 4.14.9 (#1562)

Merge pull request #1507 from wazuh/change/1506-add-dev-image-construction-in-4x

Add dev image build tooling for 4.14.x
# Conflicts:
#	dev-tools/build-dev-image/README.md
#	dev-tools/build-dev-image/build-multiarch.sh
#	dev-tools/build-dev-image/install-plugins.sh
#	dev-tools/build-dev-image/plugins
#	dev-tools/build-dev-image/warmup-opensearch_dashboards.yml
#	dev-tools/build-dev-image/warmup-optimizer.sh
#	dev-tools/build-dev-image/wzd.dockerfile

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Rodrigo López <37187963+rodrigofez@users.noreply.github.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Wazuh CI <22834044+wazuhci@users.noreply.github.com>
yenienserrano added a commit that referenced this pull request Sep 4, 2026
* Merge 5.0.0 into 5.0.1 (#1518)

* Report skipped bumps in the repository bumper workflow (#1492)

Improve repository bumper error handling

* Recalculate flyout position when the sidecar is opened (#1503)

* Adapt flyout position in relation to the sidecar

* Add changelog

* Change resizable button emphasis style from :focus to :active (#1508)

* fix(sidecar): change resizable button emphasis style from :focus to :active

Update the .sidecar-resizableButton CSS to emphasize the "grab" icon
on :active instead of :focus, matching the intended interaction
feedback when dragging the resizer.

Closes wazuh/wazuh-dashboard-plugins#8989

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* fix(sidecar): remove leftover native focus outline on resizable button

The resizable button programmatically calls .focus() on every click,
so after removing the custom :focus emphasis in favor of :active, the
browser's default focus outline was left showing as an unstyled
colored border until focus moved elsewhere. Suppress it for
mouse/touch interaction while keeping it for keyboard users via
:focus-visible.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* fix(sidecar): opt out resizable button from the global focus-ring animation

The resizable button programmatically calls .focus() on every click,
which triggered OSD's global brute-force focus-ring animation
(:focus:not([class^="eui"]):not(.osd-resetFocusState) in _base.scss)
since the button isn't an EUI component. That showed as a lingering
colored border after dragging, independent from the button's own
:active styling. Opt out via the "osd-resetFocusState" class, which is
the mechanism _base.scss already documents for components with
hand-crafted focus states, instead of fighting the rule's
!important/specificity locally. Supersedes the previous outline:none
attempt, which didn't target the actual animation.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* feat(sidecar): allow configuring the resizable button className

Add an optional className prop to ResizableButton, and forward it from
a new classNameButton option on OverlaySidecarOpenOptions/Sidecar, so
callers of overlays.sidecar.open() can style/opt-out the resizer
button (e.g. pass "osd-resetFocusState" to drop the global focus-ring
animation) without hardcoding it in the component.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude <noreply@anthropic.com>

* Change top bar health-check icon (#1505)

* feat: update health check indicator

* Change top bar health-check icon to a pulse shown only when attention is needed

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>

* fix(core): use kebab-case for sidecar docked-mode CSS variable

Rename --osdSidecarSize to --osd-sidecar-size and switch attribute
selectors to double quotes to satisfy the repo's stylelint rules
(custom-property-pattern, string-quotes), registering sidecar.scss
in the global selectors allowlist for its .euiFlyout references.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* chore: use constant

* Rework health-check popover

* Rework health-check popover

* List failing health checks in the nav-button popover

Show the enabled non-green checks as an EuiHealth list in the health-check
popover, labelled by the check name and with the error surfaced in a tooltip.
Use the shared mapTaskStatusToHealthColor helper and TASK.RUN_RESULT constants
instead of magic strings.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>

* Fix popover closes when clicking inside

* Close popover after navigating to the health check

---------

Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>

* Bump 5.0.0 branch (#1513)

feat: bump 5.0.0

* Fix RPM changelog entry order causing build failure (#1516)

Fix RPM changelog entry order for 5.0.0

The 5.0.0 changelog entry was placed out of descending chronological
order, causing rpmbuild to fail while parsing %changelog.

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* Merge 4.14.9 into 5.0.0 (#1517)

Remove unnecessary debhelper install-time dependency (#1484)

fix: remove unnecessary debhelper install-time dependency

debhelper is only required to build the .deb package (declared under
Build-Depends in dev-tools/build-packages/deb/debian/control), not to
install a pre-built one. Remove it from the apt-get install steps used
to test package install/upgrade.

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Rodrigo López <37187963+rodrigofez@users.noreply.github.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Wazuh CI <22834044+wazuhci@users.noreply.github.com>

* Merge 5.0.0 into 5.0.1 (#1541)

* Report skipped bumps in the repository bumper workflow (#1492)

Improve repository bumper error handling

* Recalculate flyout position when the sidecar is opened (#1503)

* Adapt flyout position in relation to the sidecar

* Add changelog

* Change resizable button emphasis style from :focus to :active (#1508)

* fix(sidecar): change resizable button emphasis style from :focus to :active

Update the .sidecar-resizableButton CSS to emphasize the "grab" icon
on :active instead of :focus, matching the intended interaction
feedback when dragging the resizer.

Closes wazuh/wazuh-dashboard-plugins#8989

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* fix(sidecar): remove leftover native focus outline on resizable button

The resizable button programmatically calls .focus() on every click,
so after removing the custom :focus emphasis in favor of :active, the
browser's default focus outline was left showing as an unstyled
colored border until focus moved elsewhere. Suppress it for
mouse/touch interaction while keeping it for keyboard users via
:focus-visible.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* fix(sidecar): opt out resizable button from the global focus-ring animation

The resizable button programmatically calls .focus() on every click,
which triggered OSD's global brute-force focus-ring animation
(:focus:not([class^="eui"]):not(.osd-resetFocusState) in _base.scss)
since the button isn't an EUI component. That showed as a lingering
colored border after dragging, independent from the button's own
:active styling. Opt out via the "osd-resetFocusState" class, which is
the mechanism _base.scss already documents for components with
hand-crafted focus states, instead of fighting the rule's
!important/specificity locally. Supersedes the previous outline:none
attempt, which didn't target the actual animation.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* feat(sidecar): allow configuring the resizable button className

Add an optional className prop to ResizableButton, and forward it from
a new classNameButton option on OverlaySidecarOpenOptions/Sidecar, so
callers of overlays.sidecar.open() can style/opt-out the resizer
button (e.g. pass "osd-resetFocusState" to drop the global focus-ring
animation) without hardcoding it in the component.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude <noreply@anthropic.com>

* Change top bar health-check icon (#1505)

* feat: update health check indicator

* Change top bar health-check icon to a pulse shown only when attention is needed

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>

* fix(core): use kebab-case for sidecar docked-mode CSS variable

Rename --osdSidecarSize to --osd-sidecar-size and switch attribute
selectors to double quotes to satisfy the repo's stylelint rules
(custom-property-pattern, string-quotes), registering sidecar.scss
in the global selectors allowlist for its .euiFlyout references.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* chore: use constant

* Rework health-check popover

* Rework health-check popover

* List failing health checks in the nav-button popover

Show the enabled non-green checks as an EuiHealth list in the health-check
popover, labelled by the check name and with the error surfaced in a tooltip.
Use the shared mapTaskStatusToHealthColor helper and TASK.RUN_RESULT constants
instead of magic strings.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>

* Fix popover closes when clicking inside

* Close popover after navigating to the health check

---------

Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>

* Bump 5.0.0 branch (#1513)

feat: bump 5.0.0

* Fix RPM changelog entry order causing build failure (#1516)

Fix RPM changelog entry order for 5.0.0

The 5.0.0 changelog entry was placed out of descending chronological
order, causing rpmbuild to fail while parsing %changelog.

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* Merge 4.14.9 into 5.0.0 (#1517)

Remove unnecessary debhelper install-time dependency (#1484)

fix: remove unnecessary debhelper install-time dependency

debhelper is only required to build the .deb package (declared under
Build-Depends in dev-tools/build-packages/deb/debian/control), not to
install a pre-built one. Remove it from the apt-get install steps used
to test package install/upgrade.

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>

* Merge 4.14.9 into 5.0.0 (#1537)

Merge 4.14.9 into 5.0.0: no changes (verified 2026-08-28)

* fix: remove inert opensearch_security.cookie.ttl setting (#1534)

The dashboard config declares opensearch_security.cookie.ttl, but the
security plugin never reads it: only opensearch_security.session.ttl
governs session/cookie expiry. Shipping the setting misleads operators
into believing it bounds the cookie lifetime.

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude <noreply@anthropic.com>

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Rodrigo López <37187963+rodrigofez@users.noreply.github.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Wazuh CI <22834044+wazuhci@users.noreply.github.com>

* Merge 5.0.0 into 5.0.1 (#1564)

* Report skipped bumps in the repository bumper workflow (#1492)

Improve repository bumper error handling

* Recalculate flyout position when the sidecar is opened (#1503)

* Adapt flyout position in relation to the sidecar

* Add changelog

* Change resizable button emphasis style from :focus to :active (#1508)

* fix(sidecar): change resizable button emphasis style from :focus to :active

Update the .sidecar-resizableButton CSS to emphasize the "grab" icon
on :active instead of :focus, matching the intended interaction
feedback when dragging the resizer.

Closes wazuh/wazuh-dashboard-plugins#8989

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* fix(sidecar): remove leftover native focus outline on resizable button

The resizable button programmatically calls .focus() on every click,
so after removing the custom :focus emphasis in favor of :active, the
browser's default focus outline was left showing as an unstyled
colored border until focus moved elsewhere. Suppress it for
mouse/touch interaction while keeping it for keyboard users via
:focus-visible.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* fix(sidecar): opt out resizable button from the global focus-ring animation

The resizable button programmatically calls .focus() on every click,
which triggered OSD's global brute-force focus-ring animation
(:focus:not([class^="eui"]):not(.osd-resetFocusState) in _base.scss)
since the button isn't an EUI component. That showed as a lingering
colored border after dragging, independent from the button's own
:active styling. Opt out via the "osd-resetFocusState" class, which is
the mechanism _base.scss already documents for components with
hand-crafted focus states, instead of fighting the rule's
!important/specificity locally. Supersedes the previous outline:none
attempt, which didn't target the actual animation.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* feat(sidecar): allow configuring the resizable button className

Add an optional className prop to ResizableButton, and forward it from
a new classNameButton option on OverlaySidecarOpenOptions/Sidecar, so
callers of overlays.sidecar.open() can style/opt-out the resizer
button (e.g. pass "osd-resetFocusState" to drop the global focus-ring
animation) without hardcoding it in the component.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude <noreply@anthropic.com>

* Change top bar health-check icon (#1505)

* feat: update health check indicator

* Change top bar health-check icon to a pulse shown only when attention is needed

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>

* fix(core): use kebab-case for sidecar docked-mode CSS variable

Rename --osdSidecarSize to --osd-sidecar-size and switch attribute
selectors to double quotes to satisfy the repo's stylelint rules
(custom-property-pattern, string-quotes), registering sidecar.scss
in the global selectors allowlist for its .euiFlyout references.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>

* chore: use constant

* Rework health-check popover

* Rework health-check popover

* List failing health checks in the nav-button popover

Show the enabled non-green checks as an EuiHealth list in the health-check
popover, labelled by the check name and with the error surfaced in a tooltip.
Use the shared mapTaskStatusToHealthColor helper and TASK.RUN_RESULT constants
instead of magic strings.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>

* Fix popover closes when clicking inside

* Close popover after navigating to the health check

---------

Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>

* Bump 5.0.0 branch (#1513)

feat: bump 5.0.0

* Fix RPM changelog entry order causing build failure (#1516)

Fix RPM changelog entry order for 5.0.0

The 5.0.0 changelog entry was placed out of descending chronological
order, causing rpmbuild to fail while parsing %changelog.

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* Merge 4.14.9 into 5.0.0 (#1517)

Remove unnecessary debhelper install-time dependency (#1484)

fix: remove unnecessary debhelper install-time dependency

debhelper is only required to build the .deb package (declared under
Build-Depends in dev-tools/build-packages/deb/debian/control), not to
install a pre-built one. Remove it from the apt-get install steps used
to test package install/upgrade.

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>

* Merge 4.14.9 into 5.0.0 (#1537)

Merge 4.14.9 into 5.0.0: no changes (verified 2026-08-28)

* fix: remove inert opensearch_security.cookie.ttl setting (#1534)

The dashboard config declares opensearch_security.cookie.ttl, but the
security plugin never reads it: only opensearch_security.session.ttl
governs session/cookie expiry. Shipping the setting misleads operators
into believing it bounds the cookie lifetime.

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Claude <noreply@anthropic.com>

* Bump 5.0.0 branch (#1545)

feat: bump 5.0.0

* Revert bump 5.0.0 branch (#1546)

feat: revert 5.0.0 references

* Fix changelog not in descending chronological order (#1548)

* fix: keep RPM changelog entries in descending date order on re-bump (#1549)

Re-bumping an existing version updated its date in place instead of
repositioning it, so a newer date could end up below older entries and
rpmbuild rejected the spec (%changelog not in descending chronological
order). The entry is now removed and reinserted at the position
matching its date.

Also fixes date/sed portability on macOS (BSD date/sed vs GNU), and
makes an invalid date abort the script instead of writing the error
text into the changelog.

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* Bump 5.0.0 branch (#1551)

feat: bump 5.0.0

* Review the 5.0.0 changelog (#1556)

* docs(changelog): review the 5.0.0 entries

Removed the open redirect fix entry (#1285) and the pre install script
check entry (#1328, #1365).

Reordered the sections to Added, Changed, Removed, Fixed, and qualified
the two wazuh-dashboard-plugins references so they no longer read as
wazuh-dashboard issues.

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* docs(changelog): reference issues instead of pull requests

Each entry now links the issue the pull request closed, so the reference
carries the description and the discussion instead of just the diff.

Where an entry listed several references that resolve the same issue, it
collapses to that one; where they resolve different issues, the entry
keeps the main one and the rest are attached to it as sub-issues on
GitHub, following the shape of wazuh-dashboard-plugins#8789.

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* docs(changelog): merge the health check service and app entries

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>

* docs(changelog): point the health check entry at its parent issue

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>

---------

Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Merge 4.14.9 into 5.0.0 (#1563)

Merge 4.14.8 into 4.14.9 (#1562)

Merge pull request #1507 from wazuh/change/1506-add-dev-image-construction-in-4x

Add dev image build tooling for 4.14.x
# Conflicts:
#	dev-tools/build-dev-image/README.md
#	dev-tools/build-dev-image/build-multiarch.sh
#	dev-tools/build-dev-image/install-plugins.sh
#	dev-tools/build-dev-image/plugins
#	dev-tools/build-dev-image/warmup-opensearch_dashboards.yml
#	dev-tools/build-dev-image/warmup-optimizer.sh
#	dev-tools/build-dev-image/wzd.dockerfile

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Rodrigo López <37187963+rodrigofez@users.noreply.github.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Wazuh CI <22834044+wazuhci@users.noreply.github.com>

* Update header help menu snapshot to the 5.1 documentation URL

WAZUH_DOCUMENTATION_URL is derived from the product version, so on main it
now resolves to https://documentation.wazuh.com/5.1/ while the committed
snapshot still held 5.0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Signed-off-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Signed-off-by: Rodrigo Lopez <rodrigo.lopez@wazuh.com>
Signed-off-by: Ian Yenien Serrano <63758389+yenienserrano@users.noreply.github.com>
Co-authored-by: Federico Rodriguez <federico.rodriguez@wazuh.com>
Co-authored-by: Antonio <34042064+Desvelao@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Rodrigo López <37187963+rodrigofez@users.noreply.github.com>
Co-authored-by: Antonio David Gutiérrez <antonio.gutierrez@wazuh.com>
Co-authored-by: Wazuh CI <22834044+wazuhci@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants