Skip to content

chore(axios,appex-qa,appex-operations): remove axios from shared test infrastructure - #268531

Merged
Ikuni17 merged 2 commits into
elastic:mainfrom
azasypkin:issue-2244-remove-axios-phase-5
May 15, 2026
Merged

Ikuni17 merged 2 commits into
elastic:mainfrom
azasypkin:issue-2244-remove-axios-phase-5

Conversation

@azasypkin

@azasypkin azasypkin commented May 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Phase 5 of the multi-PR axios → native fetch migration: removes axios from the shared FTR test infrastructure (Kibana Operations & QA area) and updates the catch handlers across the codebase that depended on the old AxiosError shape.

The bulk of the change is in @kbn/kbn-client, @kbn/test-saml-auth, @kbn/journeys, and @kbn/failed-test-reporter-cli. Several downstream consumer files were touched to adapt to the new KbnClientRequesterError / KbnClientResponse<T> contracts.

Predecessor PRs: #266556 (lint freeze), #266771, #267512, #267684, #267944.

Behavior parity

Important

KbnClient's public API is preserved. request() still returns { data, status, statusText, headers } (now typed KbnClientResponse<T>), destructured call sites like const { data } = await kbnClient.request(...) keep working unchanged.

  • Error shape: KbnClientRequesterError now exposes .status and .headers (a Headers instance) directly, instead of carrying a nested AxiosError via .axiosError. The underlying error is reachable via Error.cause. The error message format is [METHOD url] STATUS STATUSTEXT -- BODY.
  • URL credentials: native fetch rejects user:pass@host URLs. The requester strips them at construction time and forwards as a Basic Authorization header. resolveUrl() still returns the credentialed URL for FTR connector tests that extract user/password from it.
  • Multipart uploads: KbnClient.importExport.load now uses the native (WHATWG) FormData + Blob. fetch handles the multipart boundary itself, the legacy form-data package is dropped from this package.
  • undici dispatcher replaces https.Agent for self-signed-cert acceptance in FTR.
  • ignoreErrors still returns the parsed body envelope on the listed status (matching axios's old behavior), no more data: undefined on ignored 4xx.

Code owner notes

Important

This is one PR touching 13 CODEOWNER groups because the contract change in @kbn/kbn-client (kibana-operations + appex-qa) rippled into every consumer that reads the error shape. Splitting it would have left CI red - every consumer file had to land in one go.

@azasypkin azasypkin added chore release_note:skip Skip the PR/issue when compiling release notes backport:all-open Backport to all branches that could still receive a release labels May 8, 2026
@azasypkin
azasypkin force-pushed the issue-2244-remove-axios-phase-5 branch 6 times, most recently from 239e4e5 to aab4aca Compare May 12, 2026 08:23
@azasypkin
azasypkin force-pushed the issue-2244-remove-axios-phase-5 branch from aab4aca to 6541533 Compare May 12, 2026 18:39
@azasypkin azasypkin changed the title chore(axios,appex-qa): remove axios from shared test infrastructure chore(axios,appex-qa,appex-operations): remove axios from shared test infrastructure May 12, 2026
@azasypkin
azasypkin marked this pull request as ready for review May 12, 2026 20:11
@azasypkin
azasypkin requested review from a team as code owners May 12, 2026 20:11
@azasypkin
azasypkin requested a review from a team May 12, 2026 20:11
@azasypkin
azasypkin requested review from a team as code owners May 12, 2026 20:11
@azasypkin
azasypkin requested a review from a team May 12, 2026 20:11
@azasypkin
azasypkin requested a review from a team as a code owner May 12, 2026 20:11
@github-actions

Copy link
Copy Markdown
Contributor

🤖 GitHub comments

Expand to view the GitHub comments

Just comment with:

  • /oblt-deploy : Deploy a Kibana instance using the Observability test environments.
  • run docs-build : Re-trigger the docs validation. (use unformatted text in the comment!)

@Ikuni17
Ikuni17 disabled auto-merge May 15, 2026 11:55
@Ikuni17
Ikuni17 merged commit 70c5bba into elastic:main May 15, 2026
47 of 48 checks passed
@azasypkin
azasypkin deleted the issue-2244-remove-axios-phase-5 branch May 15, 2026 11:56
@kibanamachine

Copy link
Copy Markdown
Contributor

Starting backport for target branches: 8.19, 9.3, 9.4

https://github.com/elastic/kibana/actions/runs/25916477685

@kibanamachine

Copy link
Copy Markdown
Contributor

💔 Some backports could not be created

Status Branch Result
❌ 8.19 Backport failed because of merge conflicts
❌ 9.3 Backport failed because of merge conflicts
✅ 9.4

Note: Successful backport PRs will be merged automatically after passing CI.

Manual backport

To create the backport manually run:

node scripts/backport --pr 268531

Questions ?

Please refer to the Backport tool documentation

kibanamachine added a commit that referenced this pull request May 15, 2026
…d test infrastructure (#268531) (#269492)

# Backport

This will backport the following commits from `main` to `9.4`:
- [chore(axios,appex-qa,appex-operations): remove axios from shared test
infrastructure (#268531)](#268531)

<!--- Backport version: 9.6.6 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sorenlouv/backport)

<!--BACKPORT [{"author":{"name":"Aleh
Zasypkin","email":"aleh.zasypkin@elastic.co"},"sourceCommit":{"committedDate":"2026-05-15T11:55:47Z","message":"chore(axios,appex-qa,appex-operations):
remove axios from shared test infrastructure (#268531)\n\n##
Summary\n\nPhase 5 of the multi-PR `axios` → native `fetch` migration:
removes\n`axios` from the shared FTR test infrastructure (Kibana
Operations & QA\narea) and updates the catch handlers across the
codebase that depended\non the old `AxiosError` shape.\n\nThe bulk of
the change is in `@kbn/kbn-client`,
`@kbn/test-saml-auth`,\n`@kbn/journeys`, and
`@kbn/failed-test-reporter-cli`. Several downstream\nconsumer files were
touched to adapt to the new\n`KbnClientRequesterError` /
`KbnClientResponse<T>` contracts.\n\nPredecessor PRs: #266556 (lint
freeze), #266771, #267512, #267684,\n#267944.\n\n## Behavior parity\n\n>
[!IMPORTANT]\n> **`KbnClient`'s public API is preserved.** `request()`
still returns\n`{ data, status, statusText, headers }` (now
typed\n`KbnClientResponse<T>`), destructured call sites like `const {
data } =\nawait kbnClient.request(...)` keep working unchanged.\n\n-
**Error shape**: `KbnClientRequesterError` now exposes `.status`
and\n`.headers` (a `Headers` instance) directly, instead of carrying a
nested\n`AxiosError` via `.axiosError`. The underlying error is
reachable via\n`Error.cause`. The error message format is `[METHOD url]
STATUS\nSTATUSTEXT -- BODY`.\n- **URL credentials**: native fetch
rejects `user:pass@host` URLs. The\nrequester strips them at
construction time and forwards as a `Basic`\nAuthorization header.
`resolveUrl()` still returns the credentialed URL\nfor FTR connector
tests that extract user/password from it.\n- **Multipart uploads**:
`KbnClient.importExport.load` now uses the\nnative (WHATWG) `FormData` +
`Blob`. `fetch` handles the multipart\nboundary itself, the legacy
`form-data` package is dropped from this\npackage.\n- **`undici`
dispatcher** replaces `https.Agent` for self-signed-cert\nacceptance in
FTR.\n- **`ignoreErrors`** still returns the parsed body envelope on
the\nlisted status (matching axios's old behavior), no more `data:
undefined`\non ignored 4xx.\n\n## Code owner notes\n\n> [!IMPORTANT]\n>
This is one PR touching 13 CODEOWNER groups because the contract\nchange
in `@kbn/kbn-client` (kibana-operations + appex-qa) rippled into\nevery
consumer that reads the error shape. Splitting it would have left\nCI
red - every consumer file had to land in one
go.","sha":"70c5bba5017e2632e0c9c3bbdded3b0029a1d5b9","branchLabelMapping":{"^v9.5.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["chore","release_note:skip","Team:Fleet","ci:all-cypress-suites","backport:all-open","ci:project-deploy-observability","Team:obs-presentation","v9.5.0"],"title":"chore(axios,appex-qa,appex-operations):
remove axios from shared test
infrastructure","number":268531,"url":"https://github.com/elastic/kibana/pull/268531","mergeCommit":{"message":"chore(axios,appex-qa,appex-operations):
remove axios from shared test infrastructure (#268531)\n\n##
Summary\n\nPhase 5 of the multi-PR `axios` → native `fetch` migration:
removes\n`axios` from the shared FTR test infrastructure (Kibana
Operations & QA\narea) and updates the catch handlers across the
codebase that depended\non the old `AxiosError` shape.\n\nThe bulk of
the change is in `@kbn/kbn-client`,
`@kbn/test-saml-auth`,\n`@kbn/journeys`, and
`@kbn/failed-test-reporter-cli`. Several downstream\nconsumer files were
touched to adapt to the new\n`KbnClientRequesterError` /
`KbnClientResponse<T>` contracts.\n\nPredecessor PRs: #266556 (lint
freeze), #266771, #267512, #267684,\n#267944.\n\n## Behavior parity\n\n>
[!IMPORTANT]\n> **`KbnClient`'s public API is preserved.** `request()`
still returns\n`{ data, status, statusText, headers }` (now
typed\n`KbnClientResponse<T>`), destructured call sites like `const {
data } =\nawait kbnClient.request(...)` keep working unchanged.\n\n-
**Error shape**: `KbnClientRequesterError` now exposes `.status`
and\n`.headers` (a `Headers` instance) directly, instead of carrying a
nested\n`AxiosError` via `.axiosError`. The underlying error is
reachable via\n`Error.cause`. The error message format is `[METHOD url]
STATUS\nSTATUSTEXT -- BODY`.\n- **URL credentials**: native fetch
rejects `user:pass@host` URLs. The\nrequester strips them at
construction time and forwards as a `Basic`\nAuthorization header.
`resolveUrl()` still returns the credentialed URL\nfor FTR connector
tests that extract user/password from it.\n- **Multipart uploads**:
`KbnClient.importExport.load` now uses the\nnative (WHATWG) `FormData` +
`Blob`. `fetch` handles the multipart\nboundary itself, the legacy
`form-data` package is dropped from this\npackage.\n- **`undici`
dispatcher** replaces `https.Agent` for self-signed-cert\nacceptance in
FTR.\n- **`ignoreErrors`** still returns the parsed body envelope on
the\nlisted status (matching axios's old behavior), no more `data:
undefined`\non ignored 4xx.\n\n## Code owner notes\n\n> [!IMPORTANT]\n>
This is one PR touching 13 CODEOWNER groups because the contract\nchange
in `@kbn/kbn-client` (kibana-operations + appex-qa) rippled into\nevery
consumer that reads the error shape. Splitting it would have left\nCI
red - every consumer file had to land in one
go.","sha":"70c5bba5017e2632e0c9c3bbdded3b0029a1d5b9"}},"sourceBranch":"main","suggestedTargetBranches":[],"targetPullRequestStates":[{"branch":"main","label":"v9.5.0","branchLabelMappingKey":"^v9.5.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/268531","number":268531,"mergeCommit":{"message":"chore(axios,appex-qa,appex-operations):
remove axios from shared test infrastructure (#268531)\n\n##
Summary\n\nPhase 5 of the multi-PR `axios` → native `fetch` migration:
removes\n`axios` from the shared FTR test infrastructure (Kibana
Operations & QA\narea) and updates the catch handlers across the
codebase that depended\non the old `AxiosError` shape.\n\nThe bulk of
the change is in `@kbn/kbn-client`,
`@kbn/test-saml-auth`,\n`@kbn/journeys`, and
`@kbn/failed-test-reporter-cli`. Several downstream\nconsumer files were
touched to adapt to the new\n`KbnClientRequesterError` /
`KbnClientResponse<T>` contracts.\n\nPredecessor PRs: #266556 (lint
freeze), #266771, #267512, #267684,\n#267944.\n\n## Behavior parity\n\n>
[!IMPORTANT]\n> **`KbnClient`'s public API is preserved.** `request()`
still returns\n`{ data, status, statusText, headers }` (now
typed\n`KbnClientResponse<T>`), destructured call sites like `const {
data } =\nawait kbnClient.request(...)` keep working unchanged.\n\n-
**Error shape**: `KbnClientRequesterError` now exposes `.status`
and\n`.headers` (a `Headers` instance) directly, instead of carrying a
nested\n`AxiosError` via `.axiosError`. The underlying error is
reachable via\n`Error.cause`. The error message format is `[METHOD url]
STATUS\nSTATUSTEXT -- BODY`.\n- **URL credentials**: native fetch
rejects `user:pass@host` URLs. The\nrequester strips them at
construction time and forwards as a `Basic`\nAuthorization header.
`resolveUrl()` still returns the credentialed URL\nfor FTR connector
tests that extract user/password from it.\n- **Multipart uploads**:
`KbnClient.importExport.load` now uses the\nnative (WHATWG) `FormData` +
`Blob`. `fetch` handles the multipart\nboundary itself, the legacy
`form-data` package is dropped from this\npackage.\n- **`undici`
dispatcher** replaces `https.Agent` for self-signed-cert\nacceptance in
FTR.\n- **`ignoreErrors`** still returns the parsed body envelope on
the\nlisted status (matching axios's old behavior), no more `data:
undefined`\non ignored 4xx.\n\n## Code owner notes\n\n> [!IMPORTANT]\n>
This is one PR touching 13 CODEOWNER groups because the contract\nchange
in `@kbn/kbn-client` (kibana-operations + appex-qa) rippled into\nevery
consumer that reads the error shape. Splitting it would have left\nCI
red - every consumer file had to land in one
go.","sha":"70c5bba5017e2632e0c9c3bbdded3b0029a1d5b9"}}]}] BACKPORT-->

Co-authored-by: Aleh Zasypkin <aleh.zasypkin@elastic.co>
@azasypkin

Copy link
Copy Markdown
Contributor Author

💚 All backports created successfully

Status Branch Result
✅ 9.3
✅ 8.19

Note: Successful backport PRs will be merged automatically after passing CI.

Questions ?

Please refer to the Backport tool documentation

azasypkin added a commit that referenced this pull request May 15, 2026
…d test infrastructure (#268531) (#269526)

# Backport

This will backport the following commits from `main` to `9.3`:
- [chore(axios,appex-qa,appex-operations): remove axios from shared test
infrastructure (#268531)](#268531)

<!--- Backport version: 11.0.2 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sorenlouv/backport)

<!--BACKPORT [{"author":{"name":"Aleh
Zasypkin","email":"aleh.zasypkin@elastic.co"},"sourceCommit":{"committedDate":"2026-05-15T11:55:47Z","message":"chore(axios,appex-qa,appex-operations):
remove axios from shared test infrastructure (#268531)\n\n##
Summary\n\nPhase 5 of the multi-PR `axios` → native `fetch` migration:
removes\n`axios` from the shared FTR test infrastructure (Kibana
Operations & QA\narea) and updates the catch handlers across the
codebase that depended\non the old `AxiosError` shape.\n\nThe bulk of
the change is in `@kbn/kbn-client`,
`@kbn/test-saml-auth`,\n`@kbn/journeys`, and
`@kbn/failed-test-reporter-cli`. Several downstream\nconsumer files were
touched to adapt to the new\n`KbnClientRequesterError` /
`KbnClientResponse<T>` contracts.\n\nPredecessor PRs: #266556 (lint
freeze), #266771, #267512, #267684,\n#267944.\n\n## Behavior parity\n\n>
[!IMPORTANT]\n> **`KbnClient`'s public API is preserved.** `request()`
still returns\n`{ data, status, statusText, headers }` (now
typed\n`KbnClientResponse<T>`), destructured call sites like `const {
data } =\nawait kbnClient.request(...)` keep working unchanged.\n\n-
**Error shape**: `KbnClientRequesterError` now exposes `.status`
and\n`.headers` (a `Headers` instance) directly, instead of carrying a
nested\n`AxiosError` via `.axiosError`. The underlying error is
reachable via\n`Error.cause`. The error message format is `[METHOD url]
STATUS\nSTATUSTEXT -- BODY`.\n- **URL credentials**: native fetch
rejects `user:pass@host` URLs. The\nrequester strips them at
construction time and forwards as a `Basic`\nAuthorization header.
`resolveUrl()` still returns the credentialed URL\nfor FTR connector
tests that extract user/password from it.\n- **Multipart uploads**:
`KbnClient.importExport.load` now uses the\nnative (WHATWG) `FormData` +
`Blob`. `fetch` handles the multipart\nboundary itself, the legacy
`form-data` package is dropped from this\npackage.\n- **`undici`
dispatcher** replaces `https.Agent` for self-signed-cert\nacceptance in
FTR.\n- **`ignoreErrors`** still returns the parsed body envelope on
the\nlisted status (matching axios's old behavior), no more `data:
undefined`\non ignored 4xx.\n\n## Code owner notes\n\n> [!IMPORTANT]\n>
This is one PR touching 13 CODEOWNER groups because the contract\nchange
in `@kbn/kbn-client` (kibana-operations + appex-qa) rippled into\nevery
consumer that reads the error shape. Splitting it would have left\nCI
red - every consumer file had to land in one
go.","sha":"70c5bba5017e2632e0c9c3bbdded3b0029a1d5b9","branchLabelMapping":{"^v9.5.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["chore","release_note:skip","Team:Fleet","ci:all-cypress-suites","backport:all-open","ci:project-deploy-observability","Team:obs-presentation","v9.5.0","v9.4.2"],"title":"chore(axios,appex-qa,appex-operations):
remove axios from shared test
infrastructure","number":268531,"url":"https://github.com/elastic/kibana/pull/268531","mergeCommit":{"message":"chore(axios,appex-qa,appex-operations):
remove axios from shared test infrastructure (#268531)\n\n##
Summary\n\nPhase 5 of the multi-PR `axios` → native `fetch` migration:
removes\n`axios` from the shared FTR test infrastructure (Kibana
Operations & QA\narea) and updates the catch handlers across the
codebase that depended\non the old `AxiosError` shape.\n\nThe bulk of
the change is in `@kbn/kbn-client`,
`@kbn/test-saml-auth`,\n`@kbn/journeys`, and
`@kbn/failed-test-reporter-cli`. Several downstream\nconsumer files were
touched to adapt to the new\n`KbnClientRequesterError` /
`KbnClientResponse<T>` contracts.\n\nPredecessor PRs: #266556 (lint
freeze), #266771, #267512, #267684,\n#267944.\n\n## Behavior parity\n\n>
[!IMPORTANT]\n> **`KbnClient`'s public API is preserved.** `request()`
still returns\n`{ data, status, statusText, headers }` (now
typed\n`KbnClientResponse<T>`), destructured call sites like `const {
data } =\nawait kbnClient.request(...)` keep working unchanged.\n\n-
**Error shape**: `KbnClientRequesterError` now exposes `.status`
and\n`.headers` (a `Headers` instance) directly, instead of carrying a
nested\n`AxiosError` via `.axiosError`. The underlying error is
reachable via\n`Error.cause`. The error message format is `[METHOD url]
STATUS\nSTATUSTEXT -- BODY`.\n- **URL credentials**: native fetch
rejects `user:pass@host` URLs. The\nrequester strips them at
construction time and forwards as a `Basic`\nAuthorization header.
`resolveUrl()` still returns the credentialed URL\nfor FTR connector
tests that extract user/password from it.\n- **Multipart uploads**:
`KbnClient.importExport.load` now uses the\nnative (WHATWG) `FormData` +
`Blob`. `fetch` handles the multipart\nboundary itself, the legacy
`form-data` package is dropped from this\npackage.\n- **`undici`
dispatcher** replaces `https.Agent` for self-signed-cert\nacceptance in
FTR.\n- **`ignoreErrors`** still returns the parsed body envelope on
the\nlisted status (matching axios's old behavior), no more `data:
undefined`\non ignored 4xx.\n\n## Code owner notes\n\n> [!IMPORTANT]\n>
This is one PR touching 13 CODEOWNER groups because the contract\nchange
in `@kbn/kbn-client` (kibana-operations + appex-qa) rippled into\nevery
consumer that reads the error shape. Splitting it would have left\nCI
red - every consumer file had to land in one
go.","sha":"70c5bba5017e2632e0c9c3bbdded3b0029a1d5b9"}},"sourceBranch":"main","suggestedTargetBranches":[],"targetPullRequestStates":[{"branch":"main","label":"v9.5.0","branchLabelMappingKey":"^v9.5.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/268531","number":268531,"mergeCommit":{"message":"chore(axios,appex-qa,appex-operations):
remove axios from shared test infrastructure (#268531)\n\n##
Summary\n\nPhase 5 of the multi-PR `axios` → native `fetch` migration:
removes\n`axios` from the shared FTR test infrastructure (Kibana
Operations & QA\narea) and updates the catch handlers across the
codebase that depended\non the old `AxiosError` shape.\n\nThe bulk of
the change is in `@kbn/kbn-client`,
`@kbn/test-saml-auth`,\n`@kbn/journeys`, and
`@kbn/failed-test-reporter-cli`. Several downstream\nconsumer files were
touched to adapt to the new\n`KbnClientRequesterError` /
`KbnClientResponse<T>` contracts.\n\nPredecessor PRs: #266556 (lint
freeze), #266771, #267512, #267684,\n#267944.\n\n## Behavior parity\n\n>
[!IMPORTANT]\n> **`KbnClient`'s public API is preserved.** `request()`
still returns\n`{ data, status, statusText, headers }` (now
typed\n`KbnClientResponse<T>`), destructured call sites like `const {
data } =\nawait kbnClient.request(...)` keep working unchanged.\n\n-
**Error shape**: `KbnClientRequesterError` now exposes `.status`
and\n`.headers` (a `Headers` instance) directly, instead of carrying a
nested\n`AxiosError` via `.axiosError`. The underlying error is
reachable via\n`Error.cause`. The error message format is `[METHOD url]
STATUS\nSTATUSTEXT -- BODY`.\n- **URL credentials**: native fetch
rejects `user:pass@host` URLs. The\nrequester strips them at
construction time and forwards as a `Basic`\nAuthorization header.
`resolveUrl()` still returns the credentialed URL\nfor FTR connector
tests that extract user/password from it.\n- **Multipart uploads**:
`KbnClient.importExport.load` now uses the\nnative (WHATWG) `FormData` +
`Blob`. `fetch` handles the multipart\nboundary itself, the legacy
`form-data` package is dropped from this\npackage.\n- **`undici`
dispatcher** replaces `https.Agent` for self-signed-cert\nacceptance in
FTR.\n- **`ignoreErrors`** still returns the parsed body envelope on
the\nlisted status (matching axios's old behavior), no more `data:
undefined`\non ignored 4xx.\n\n## Code owner notes\n\n> [!IMPORTANT]\n>
This is one PR touching 13 CODEOWNER groups because the contract\nchange
in `@kbn/kbn-client` (kibana-operations + appex-qa) rippled into\nevery
consumer that reads the error shape. Splitting it would have left\nCI
red - every consumer file had to land in one
go.","sha":"70c5bba5017e2632e0c9c3bbdded3b0029a1d5b9"}},{"branch":"9.4","label":"v9.4.2","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"url":"https://github.com/elastic/kibana/pull/269492","number":269492,"state":"MERGED","mergeCommit":{"sha":"051075a6610a28749b3b3e68e2d5d0067b8e7bbb","message":"[9.4]
chore(axios,appex-qa,appex-operations): remove axios from shared test
infrastructure (#268531) (#269492)\n\n# Backport\n\nThis will backport
the following commits from `main` to `9.4`:\n-
[chore(axios,appex-qa,appex-operations): remove axios from shared
test\ninfrastructure
(#268531)](https://github.com/elastic/kibana/pull/268531)\n\n\n\n###
Questions ?\nPlease refer to the [Backport
tool\ndocumentation](https://github.com/sorenlouv/backport)\n\n\n\nCo-authored-by:
Aleh Zasypkin <aleh.zasypkin@elastic.co>"}}]}] BACKPORT-->
azasypkin added a commit that referenced this pull request May 15, 2026
…ed test infrastructure (#268531) (#269537)

# Backport

This will backport the following commits from `main` to `8.19`:
- [chore(axios,appex-qa,appex-operations): remove axios from shared test
infrastructure (#268531)](#268531)

<!--- Backport version: 11.0.2 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sorenlouv/backport)

<!--BACKPORT [{"author":{"name":"Aleh
Zasypkin","email":"aleh.zasypkin@elastic.co"},"sourceCommit":{"committedDate":"2026-05-15T11:55:47Z","message":"chore(axios,appex-qa,appex-operations):
remove axios from shared test infrastructure (#268531)\n\n##
Summary\n\nPhase 5 of the multi-PR `axios` → native `fetch` migration:
removes\n`axios` from the shared FTR test infrastructure (Kibana
Operations & QA\narea) and updates the catch handlers across the
codebase that depended\non the old `AxiosError` shape.\n\nThe bulk of
the change is in `@kbn/kbn-client`,
`@kbn/test-saml-auth`,\n`@kbn/journeys`, and
`@kbn/failed-test-reporter-cli`. Several downstream\nconsumer files were
touched to adapt to the new\n`KbnClientRequesterError` /
`KbnClientResponse<T>` contracts.\n\nPredecessor PRs: #266556 (lint
freeze), #266771, #267512, #267684,\n#267944.\n\n## Behavior parity\n\n>
[!IMPORTANT]\n> **`KbnClient`'s public API is preserved.** `request()`
still returns\n`{ data, status, statusText, headers }` (now
typed\n`KbnClientResponse<T>`), destructured call sites like `const {
data } =\nawait kbnClient.request(...)` keep working unchanged.\n\n-
**Error shape**: `KbnClientRequesterError` now exposes `.status`
and\n`.headers` (a `Headers` instance) directly, instead of carrying a
nested\n`AxiosError` via `.axiosError`. The underlying error is
reachable via\n`Error.cause`. The error message format is `[METHOD url]
STATUS\nSTATUSTEXT -- BODY`.\n- **URL credentials**: native fetch
rejects `user:pass@host` URLs. The\nrequester strips them at
construction time and forwards as a `Basic`\nAuthorization header.
`resolveUrl()` still returns the credentialed URL\nfor FTR connector
tests that extract user/password from it.\n- **Multipart uploads**:
`KbnClient.importExport.load` now uses the\nnative (WHATWG) `FormData` +
`Blob`. `fetch` handles the multipart\nboundary itself, the legacy
`form-data` package is dropped from this\npackage.\n- **`undici`
dispatcher** replaces `https.Agent` for self-signed-cert\nacceptance in
FTR.\n- **`ignoreErrors`** still returns the parsed body envelope on
the\nlisted status (matching axios's old behavior), no more `data:
undefined`\non ignored 4xx.\n\n## Code owner notes\n\n> [!IMPORTANT]\n>
This is one PR touching 13 CODEOWNER groups because the contract\nchange
in `@kbn/kbn-client` (kibana-operations + appex-qa) rippled into\nevery
consumer that reads the error shape. Splitting it would have left\nCI
red - every consumer file had to land in one
go.","sha":"70c5bba5017e2632e0c9c3bbdded3b0029a1d5b9","branchLabelMapping":{"^v9.5.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["chore","release_note:skip","Team:Fleet","ci:all-cypress-suites","backport:all-open","ci:project-deploy-observability","Team:obs-presentation","v9.5.0","v9.4.2"],"title":"chore(axios,appex-qa,appex-operations):
remove axios from shared test
infrastructure","number":268531,"url":"https://github.com/elastic/kibana/pull/268531","mergeCommit":{"message":"chore(axios,appex-qa,appex-operations):
remove axios from shared test infrastructure (#268531)\n\n##
Summary\n\nPhase 5 of the multi-PR `axios` → native `fetch` migration:
removes\n`axios` from the shared FTR test infrastructure (Kibana
Operations & QA\narea) and updates the catch handlers across the
codebase that depended\non the old `AxiosError` shape.\n\nThe bulk of
the change is in `@kbn/kbn-client`,
`@kbn/test-saml-auth`,\n`@kbn/journeys`, and
`@kbn/failed-test-reporter-cli`. Several downstream\nconsumer files were
touched to adapt to the new\n`KbnClientRequesterError` /
`KbnClientResponse<T>` contracts.\n\nPredecessor PRs: #266556 (lint
freeze), #266771, #267512, #267684,\n#267944.\n\n## Behavior parity\n\n>
[!IMPORTANT]\n> **`KbnClient`'s public API is preserved.** `request()`
still returns\n`{ data, status, statusText, headers }` (now
typed\n`KbnClientResponse<T>`), destructured call sites like `const {
data } =\nawait kbnClient.request(...)` keep working unchanged.\n\n-
**Error shape**: `KbnClientRequesterError` now exposes `.status`
and\n`.headers` (a `Headers` instance) directly, instead of carrying a
nested\n`AxiosError` via `.axiosError`. The underlying error is
reachable via\n`Error.cause`. The error message format is `[METHOD url]
STATUS\nSTATUSTEXT -- BODY`.\n- **URL credentials**: native fetch
rejects `user:pass@host` URLs. The\nrequester strips them at
construction time and forwards as a `Basic`\nAuthorization header.
`resolveUrl()` still returns the credentialed URL\nfor FTR connector
tests that extract user/password from it.\n- **Multipart uploads**:
`KbnClient.importExport.load` now uses the\nnative (WHATWG) `FormData` +
`Blob`. `fetch` handles the multipart\nboundary itself, the legacy
`form-data` package is dropped from this\npackage.\n- **`undici`
dispatcher** replaces `https.Agent` for self-signed-cert\nacceptance in
FTR.\n- **`ignoreErrors`** still returns the parsed body envelope on
the\nlisted status (matching axios's old behavior), no more `data:
undefined`\non ignored 4xx.\n\n## Code owner notes\n\n> [!IMPORTANT]\n>
This is one PR touching 13 CODEOWNER groups because the contract\nchange
in `@kbn/kbn-client` (kibana-operations + appex-qa) rippled into\nevery
consumer that reads the error shape. Splitting it would have left\nCI
red - every consumer file had to land in one
go.","sha":"70c5bba5017e2632e0c9c3bbdded3b0029a1d5b9"}},"sourceBranch":"main","suggestedTargetBranches":[],"targetPullRequestStates":[{"branch":"main","label":"v9.5.0","branchLabelMappingKey":"^v9.5.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/268531","number":268531,"mergeCommit":{"message":"chore(axios,appex-qa,appex-operations):
remove axios from shared test infrastructure (#268531)\n\n##
Summary\n\nPhase 5 of the multi-PR `axios` → native `fetch` migration:
removes\n`axios` from the shared FTR test infrastructure (Kibana
Operations & QA\narea) and updates the catch handlers across the
codebase that depended\non the old `AxiosError` shape.\n\nThe bulk of
the change is in `@kbn/kbn-client`,
`@kbn/test-saml-auth`,\n`@kbn/journeys`, and
`@kbn/failed-test-reporter-cli`. Several downstream\nconsumer files were
touched to adapt to the new\n`KbnClientRequesterError` /
`KbnClientResponse<T>` contracts.\n\nPredecessor PRs: #266556 (lint
freeze), #266771, #267512, #267684,\n#267944.\n\n## Behavior parity\n\n>
[!IMPORTANT]\n> **`KbnClient`'s public API is preserved.** `request()`
still returns\n`{ data, status, statusText, headers }` (now
typed\n`KbnClientResponse<T>`), destructured call sites like `const {
data } =\nawait kbnClient.request(...)` keep working unchanged.\n\n-
**Error shape**: `KbnClientRequesterError` now exposes `.status`
and\n`.headers` (a `Headers` instance) directly, instead of carrying a
nested\n`AxiosError` via `.axiosError`. The underlying error is
reachable via\n`Error.cause`. The error message format is `[METHOD url]
STATUS\nSTATUSTEXT -- BODY`.\n- **URL credentials**: native fetch
rejects `user:pass@host` URLs. The\nrequester strips them at
construction time and forwards as a `Basic`\nAuthorization header.
`resolveUrl()` still returns the credentialed URL\nfor FTR connector
tests that extract user/password from it.\n- **Multipart uploads**:
`KbnClient.importExport.load` now uses the\nnative (WHATWG) `FormData` +
`Blob`. `fetch` handles the multipart\nboundary itself, the legacy
`form-data` package is dropped from this\npackage.\n- **`undici`
dispatcher** replaces `https.Agent` for self-signed-cert\nacceptance in
FTR.\n- **`ignoreErrors`** still returns the parsed body envelope on
the\nlisted status (matching axios's old behavior), no more `data:
undefined`\non ignored 4xx.\n\n## Code owner notes\n\n> [!IMPORTANT]\n>
This is one PR touching 13 CODEOWNER groups because the contract\nchange
in `@kbn/kbn-client` (kibana-operations + appex-qa) rippled into\nevery
consumer that reads the error shape. Splitting it would have left\nCI
red - every consumer file had to land in one
go.","sha":"70c5bba5017e2632e0c9c3bbdded3b0029a1d5b9"}},{"branch":"9.4","label":"v9.4.2","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"url":"https://github.com/elastic/kibana/pull/269492","number":269492,"state":"MERGED","mergeCommit":{"sha":"051075a6610a28749b3b3e68e2d5d0067b8e7bbb","message":"[9.4]
chore(axios,appex-qa,appex-operations): remove axios from shared test
infrastructure (#268531) (#269492)\n\n# Backport\n\nThis will backport
the following commits from `main` to `9.4`:\n-
[chore(axios,appex-qa,appex-operations): remove axios from shared
test\ninfrastructure
(#268531)](https://github.com/elastic/kibana/pull/268531)\n\n\n\n###
Questions ?\nPlease refer to the [Backport
tool\ndocumentation](https://github.com/sorenlouv/backport)\n\n\n\nCo-authored-by:
Aleh Zasypkin <aleh.zasypkin@elastic.co>"}}]}] BACKPORT-->
@azasypkin azasypkin self-assigned this May 15, 2026
rStelmach added a commit that referenced this pull request May 25, 2026
## Summary

Set `connect.timeout = 60s` on the undici `Agent` used by
`KbnClientRequester` (https path only).

## Why

#268531 migrated `KbnClient` from axios to native fetch but did not
override undici's 10s `connect.timeout` default. Axios had no equivalent
cutoff, so FTR callers talking to a busy local Kibana started failing
once that PR landed.

The `kibana-streams-performance` weekly pipeline went red in builds #9,
#11, #12, and #13 with:

```
ConnectTimeoutError: Connect Timeout Error (attempted address: localhost:5620, timeout: 10000ms)
```

The `10000ms` is undici's default. Bisect: build #8 last green
(2026-05-11) → #9 first red (2026-05-18), with #268531 in the window.

## What changed


`src/platform/packages/shared/kbn-kbn-client/src/kbn_client/kbn_client_requester.ts`:
one constant, one option on the https `Agent`. http branch unchanged.

## Related

Regression introduced in #268531. Companion streams perf PR: #270636.

## Validation

https://buildkite.com/elastic/kibana-streams-performance/builds/14
jcger pushed a commit that referenced this pull request May 26, 2026
… infrastructure (#268531)

## Summary

Phase 5 of the multi-PR `axios` → native `fetch` migration: removes
`axios` from the shared FTR test infrastructure (Kibana Operations & QA
area) and updates the catch handlers across the codebase that depended
on the old `AxiosError` shape.

The bulk of the change is in `@kbn/kbn-client`, `@kbn/test-saml-auth`,
`@kbn/journeys`, and `@kbn/failed-test-reporter-cli`. Several downstream
consumer files were touched to adapt to the new
`KbnClientRequesterError` / `KbnClientResponse<T>` contracts.

Predecessor PRs: #266556 (lint freeze), #266771, #267512, #267684,
#267944.

## Behavior parity

> [!IMPORTANT]
> **`KbnClient`'s public API is preserved.** `request()` still returns
`{ data, status, statusText, headers }` (now typed
`KbnClientResponse<T>`), destructured call sites like `const { data } =
await kbnClient.request(...)` keep working unchanged.

- **Error shape**: `KbnClientRequesterError` now exposes `.status` and
`.headers` (a `Headers` instance) directly, instead of carrying a nested
`AxiosError` via `.axiosError`. The underlying error is reachable via
`Error.cause`. The error message format is `[METHOD url] STATUS
STATUSTEXT -- BODY`.
- **URL credentials**: native fetch rejects `user:pass@host` URLs. The
requester strips them at construction time and forwards as a `Basic`
Authorization header. `resolveUrl()` still returns the credentialed URL
for FTR connector tests that extract user/password from it.
- **Multipart uploads**: `KbnClient.importExport.load` now uses the
native (WHATWG) `FormData` + `Blob`. `fetch` handles the multipart
boundary itself, the legacy `form-data` package is dropped from this
package.
- **`undici` dispatcher** replaces `https.Agent` for self-signed-cert
acceptance in FTR.
- **`ignoreErrors`** still returns the parsed body envelope on the
listed status (matching axios's old behavior), no more `data: undefined`
on ignored 4xx.

## Code owner notes

> [!IMPORTANT]
> This is one PR touching 13 CODEOWNER groups because the contract
change in `@kbn/kbn-client` (kibana-operations + appex-qa) rippled into
every consumer that reads the error shape. Splitting it would have left
CI red - every consumer file had to land in one go.
patrykkopycinski pushed a commit to patrykkopycinski/kibana that referenced this pull request Aug 5, 2026
… infrastructure (elastic#268531)

## Summary

Phase 5 of the multi-PR `axios` → native `fetch` migration: removes
`axios` from the shared FTR test infrastructure (Kibana Operations & QA
area) and updates the catch handlers across the codebase that depended
on the old `AxiosError` shape.

The bulk of the change is in `@kbn/kbn-client`, `@kbn/test-saml-auth`,
`@kbn/journeys`, and `@kbn/failed-test-reporter-cli`. Several downstream
consumer files were touched to adapt to the new
`KbnClientRequesterError` / `KbnClientResponse<T>` contracts.

Predecessor PRs: elastic#266556 (lint freeze), elastic#266771, elastic#267512, elastic#267684,
elastic#267944.

## Behavior parity

> [!IMPORTANT]
> **`KbnClient`'s public API is preserved.** `request()` still returns
`{ data, status, statusText, headers }` (now typed
`KbnClientResponse<T>`), destructured call sites like `const { data } =
await kbnClient.request(...)` keep working unchanged.

- **Error shape**: `KbnClientRequesterError` now exposes `.status` and
`.headers` (a `Headers` instance) directly, instead of carrying a nested
`AxiosError` via `.axiosError`. The underlying error is reachable via
`Error.cause`. The error message format is `[METHOD url] STATUS
STATUSTEXT -- BODY`.
- **URL credentials**: native fetch rejects `user:pass@host` URLs. The
requester strips them at construction time and forwards as a `Basic`
Authorization header. `resolveUrl()` still returns the credentialed URL
for FTR connector tests that extract user/password from it.
- **Multipart uploads**: `KbnClient.importExport.load` now uses the
native (WHATWG) `FormData` + `Blob`. `fetch` handles the multipart
boundary itself, the legacy `form-data` package is dropped from this
package.
- **`undici` dispatcher** replaces `https.Agent` for self-signed-cert
acceptance in FTR.
- **`ignoreErrors`** still returns the parsed body envelope on the
listed status (matching axios's old behavior), no more `data: undefined`
on ignored 4xx.

## Code owner notes

> [!IMPORTANT]
> This is one PR touching 13 CODEOWNER groups because the contract
change in `@kbn/kbn-client` (kibana-operations + appex-qa) rippled into
every consumer that reads the error shape. Splitting it would have left
CI red - every consumer file had to land in one go.
patrykkopycinski pushed a commit to patrykkopycinski/kibana that referenced this pull request Aug 5, 2026
## Summary

Set `connect.timeout = 60s` on the undici `Agent` used by
`KbnClientRequester` (https path only).

## Why

elastic#268531 migrated `KbnClient` from axios to native fetch but did not
override undici's 10s `connect.timeout` default. Axios had no equivalent
cutoff, so FTR callers talking to a busy local Kibana started failing
once that PR landed.

The `kibana-streams-performance` weekly pipeline went red in builds #9,
#11, #12, and #13 with:

```
ConnectTimeoutError: Connect Timeout Error (attempted address: localhost:5620, timeout: 10000ms)
```

The `10000ms` is undici's default. Bisect: build #8 last green
(2026-05-11) → #9 first red (2026-05-18), with elastic#268531 in the window.

## What changed


`src/platform/packages/shared/kbn-kbn-client/src/kbn_client/kbn_client_requester.ts`:
one constant, one option on the https `Agent`. http branch unchanged.

## Related

Regression introduced in elastic#268531. Companion streams perf PR: elastic#270636.

## Validation

https://buildkite.com/elastic/kibana-streams-performance/builds/14
azasypkin added a commit to azasypkin/kibana that referenced this pull request Aug 17, 2026
Migrates the remaining `@elastic/security-defend-workflows` axios
consumers in `security_solution` to native `fetch` and drops their three
globs from `AXIOS_LEGACY_CONSUMERS`.

Most of these files used axios only for its error type, but that is no
longer the error they receive. Since elastic#268531 `KbnClient` rejects with
`KbnClientRequesterError`, which exposes `status`, `headers` and `cause`
and has no `response`, `request`, `config` or `toJSON`. The reads left
behind are dead at runtime, and TypeScript cannot catch them because a
`catch` parameter is `any`:

- `blocklists`, `event_filters`, `host_isolation_exceptions` and
  `trusted_apps` guard list creation with `e.response.status !== 409`,
  which throws `TypeError: Cannot read properties of undefined`. The
  "list already exists" path therefore fails on every rerun instead of
  being ignored.
- `index_case.ts` compares `error.response?.status !== 404`, always
  true, then reads `error.request.method` and throws. Deleting an
  already deleted case fails instead of being ignored.
- `endpoint_response_actions.ts` checks `error?.response?.status === 404`
  so its documented 404 workaround never runs.

All of these now branch on `status`. The hand built error messages are
dropped because `KbnClientRequesterError.message` already contains the
method, url, status, status text and response body, verified against a
local server: a 409 yields
`[POST http://host/api/exception_lists] 409 Conflict -- {"statusCode":409,...}`.

`format_axios_error.ts` no longer has anything to do with axios, so it
is renamed to `format_http_error.ts`, with `FormattedAxiosError` to
`FormattedHttpError` and `catchAxiosErrorFormatAndThrow` to
`catchHttpErrorFormatAndThrow`, updating its 16 importers. The
`response.status` field is kept because callers branch on it; `request`,
`response.data` and `response.statusText` are dropped, having no
readers. Detection switches from `instanceof AxiosError` to a `status`
check. The identically named helper in `@kbn/securitysolution-utils` is
a separate copy that still uses axios, so the two files that import it
are untouched.

`fleet_services.ts` converts its three unauthenticated artifacts API
requests to inline `fetch` calls. Its remaining
`catchHttpErrorFormatAndThrow` calls wrap `KbnClient` requests and are
unchanged.

`sentinelone_host/common.ts` replaces `axios.request` with `fetch`. Only
`url` and `params` were ever passed, so the config type narrows to
those, with params stringified into `URLSearchParams`. The retry wrapper
is unchanged.

`trusted_apps/index.ts` and `endpoint_response_actions.ts` do not import
axios, so no later phase would have covered them. They are included
because they carry the same defect as their siblings.
azasypkin added a commit to azasypkin/kibana that referenced this pull request Aug 17, 2026
Migrates the remaining `@elastic/security-defend-workflows` axios
consumers in `security_solution` to native `fetch` and drops their three
globs from `AXIOS_LEGACY_CONSUMERS`.

Most of these files used axios only for its error type, but that is no
longer the error they receive. Since elastic#268531 `KbnClient` rejects with
`KbnClientRequesterError`, which exposes `status`, `headers` and `cause`
and has no `response`, `request`, `config` or `toJSON`. The reads left
behind are dead at runtime, and TypeScript cannot catch them because a
`catch` parameter is `any`:

- `blocklists`, `event_filters`, `host_isolation_exceptions` and
  `trusted_apps` guard list creation with `e.response.status !== 409`,
  which throws `TypeError: Cannot read properties of undefined`. The
  "list already exists" path therefore fails on every rerun instead of
  being ignored.
- `index_case.ts` compares `error.response?.status !== 404`, always
  true, then reads `error.request.method` and throws. Deleting an
  already deleted case fails instead of being ignored.
- `endpoint_response_actions.ts` checks `error?.response?.status === 404`
  so its documented 404 workaround never runs.

All of these now branch on `status`. The hand built error messages are
dropped because `KbnClientRequesterError.message` already contains the
method, url, status, status text and response body, verified against a
local server: a 409 yields
`[POST http://host/api/exception_lists] 409 Conflict -- {"statusCode":409,...}`.

`format_axios_error.ts` no longer has anything to do with axios, so it
is renamed to `format_http_error.ts`, with `FormattedAxiosError` to
`FormattedHttpError` and `catchAxiosErrorFormatAndThrow` to
`catchHttpErrorFormatAndThrow`, updating its 16 importers. The
`response.status` field is kept because callers branch on it; `request`,
`response.data` and `response.statusText` are dropped, having no
readers. Detection switches from `instanceof AxiosError` to a `status`
check. The identically named helper in `@kbn/securitysolution-utils` is
a separate copy that still uses axios, so the two files that import it
are untouched.

`fleet_services.ts` converts its three unauthenticated artifacts API
requests to inline `fetch` calls. Its remaining
`catchHttpErrorFormatAndThrow` calls wrap `KbnClient` requests and are
unchanged.

`sentinelone_host/common.ts` replaces `axios.request` with `fetch`. Only
`url` and `params` were ever passed, so the config type narrows to
those, with params stringified into `URLSearchParams`. The retry wrapper
is unchanged.

`trusted_apps/index.ts` and `endpoint_response_actions.ts` do not import
axios, so no later phase would have covered them. They are included
because they carry the same defect as their siblings.
azasypkin added a commit to azasypkin/kibana that referenced this pull request Aug 17, 2026
Migrates the remaining `@elastic/security-defend-workflows` axios
consumers in `security_solution` to native `fetch` and drops their three
globs from `AXIOS_LEGACY_CONSUMERS`.

Most of these files used axios only for its error type, but that is no
longer the error they receive. Since elastic#268531 `KbnClient` rejects with
`KbnClientRequesterError`, which exposes `status`, `headers` and `cause`
and has no `response`, `request`, `config` or `toJSON`. The reads left
behind are dead at runtime, and TypeScript cannot catch them because a
`catch` parameter is `any`:

- `blocklists`, `event_filters`, `host_isolation_exceptions` and
  `trusted_apps` guard list creation with `e.response.status !== 409`,
  which throws `TypeError: Cannot read properties of undefined`. The
  "list already exists" path therefore fails on every rerun instead of
  being ignored.
- `index_case.ts` compares `error.response?.status !== 404`, always
  true, then reads `error.request.method` and throws. Deleting an
  already deleted case fails instead of being ignored.
- `endpoint_response_actions.ts` checks `error?.response?.status === 404`
  so its documented 404 workaround never runs.

All of these now branch on `status`. The hand built error messages are
dropped because `KbnClientRequesterError.message` already contains the
method, url, status, status text and response body, verified against a
local server: a 409 yields
`[POST http://host/api/exception_lists] 409 Conflict -- {"statusCode":409,...}`.

`format_axios_error.ts` no longer has anything to do with axios, so it
is renamed to `format_http_error.ts`, with `FormattedAxiosError` to
`FormattedHttpError` and `catchAxiosErrorFormatAndThrow` to
`catchHttpErrorFormatAndThrow`, updating its 16 importers. The
`response.status` field is kept because callers branch on it; `request`,
`response.data` and `response.statusText` are dropped, having no
readers. Detection switches from `instanceof AxiosError` to a `status`
check. The identically named helper in `@kbn/securitysolution-utils` is
a separate copy that still uses axios, so the two files that import it
are untouched.

`fleet_services.ts` converts its three unauthenticated artifacts API
requests to inline `fetch` calls. Its remaining
`catchHttpErrorFormatAndThrow` calls wrap `KbnClient` requests and are
unchanged.

`sentinelone_host/common.ts` replaces `axios.request` with `fetch`. Only
`url` and `params` were ever passed, so the config type narrows to
those, with params stringified into `URLSearchParams`. The retry wrapper
is unchanged.

`trusted_apps/index.ts` and `endpoint_response_actions.ts` do not import
axios, so no later phase would have covered them. They are included
because they carry the same defect as their siblings.
azasypkin added a commit that referenced this pull request Aug 18, 2026
…285355)

## Summary

Part of the incremental [axios to native fetch
migration](#266556). Phase 7
covers the `@elastic/security-defend-workflows` consumers in
`security_solution` and drops their three globs from
`AXIOS_LEGACY_CONSUMERS`.

## This also fixes a live defect

Most of these files used axios only for its error type, but that is no
longer the error they receive. Since #268531 `KbnClient` rejects with
`KbnClientRequesterError`, which exposes `status`, `headers` and
`cause`, and has no `response`, `request`, `config` or `toJSON`. The
remaining reads are dead at runtime, and TypeScript cannot flag them
because a `catch` parameter is `any`:

| File | Dead check | Effect today |
| --- | --- | --- |
| `blocklists`, `event_filters`, `host_isolation_exceptions`,
`trusted_apps` | `e.response.status !== 409` | `TypeError: Cannot read
properties of undefined`, so the "list already exists" path fails on
every rerun instead of being ignored |
| `index_case.ts` | `error.response?.status !== 404` then
`error.request.method` | comparison is always true, then throws, so
deleting an already deleted case fails instead of being ignored |
| `endpoint_response_actions.ts` | `error?.response?.status === 404` |
the documented 404 workaround never runs |

These now branch on `status`. The hand built error messages are removed
because `KbnClientRequesterError.message` already carries the same
detail. Verified against a local server, a 409 produces:

```
[POST http://host/api/exception_lists] 409 Conflict -- {"statusCode":409,"message":"list id already exists"}
```

## Rename

`format_axios_error.ts` no longer has anything to do with axios, so it
becomes `format_http_error.ts`, with `FormattedAxiosError` to
`FormattedHttpError` and `catchAxiosErrorFormatAndThrow` to
`catchHttpErrorFormatAndThrow`, across its 16 importers.
`response.status` is kept because callers branch on it. `request`,
`response.data` and `response.statusText` are dropped, having no
readers. Detection switches from `instanceof AxiosError` to a `status`
check.

Note the identically named helper exported from
`@kbn/securitysolution-utils` is a separate copy that still uses axios
and is scheduled for a later phase, so the two files importing that one
are deliberately untouched.

## Other changes

- `fleet_services.ts` converts its three unauthenticated artifacts API
requests to inline `fetch` calls. Its other
`catchHttpErrorFormatAndThrow` calls wrap `KbnClient` requests and are
unchanged.
- `sentinelone_host/common.ts` replaces `axios.request` with `fetch`.
Only `url` and `params` were ever passed, so the config type narrows to
those, with params stringified into `URLSearchParams`. The retry wrapper
is unchanged.
- `trusted_apps/index.ts` and `endpoint_response_actions.ts` do not
import axios, so no later phase would have covered them. They are
included because they carry the same defect as their siblings.

## eslint allowlist

Removes the `common/endpoint/data_loaders/**`,
`common/endpoint/format_axios_error.ts` and `scripts/endpoint/**` globs.
9.4, 9.5 and 8.19 have no other axios importers under those paths, so
the backports need no per branch glob changes. `AXIOS_LEGACY_CONSUMERS`
now covers all 249 remaining consumers exactly, with no unused globs.

## Testing

- `node scripts/eslint` clean, and the global axios ban confirmed to
fire on the migrated files once the globs were removed.
- `node scripts/type_check --project
x-pack/solutions/security/plugins/security_solution/tsconfig.json`
passes.
- `node scripts/check_changes.ts` passes.
- Verified `KbnClient`'s error shape against a local server: `status` is
set, `response` / `request` / `toJSON` are absent, and the message
carries method, url, status and body.
- Exercised `S1Client` and the error helper against a mock server: query
serialization including boolean and numeric params, the `APIToken`
parameter, package parsing, download url construction, non-2xx rejection
carrying status, status text and body, and the helper's three branches.

## Backport note

`fleet_services.ts` diverges on the release branches (44 lines on 9.5,
234 on 9.4, 801 on 8.19), so that hunk will need to be re-aimed
manually. The other files are identical to main on 9.4 and 9.5, and
within 10 lines on 8.19.

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
azasypkin added a commit that referenced this pull request Aug 19, 2026
…e 7) (#285355) (#285928)

# Backport

This will backport the following commits from `main` to `9.4`:
- [chore(security, axios): migrate endpoint scripts to fetch (phase 7)
(#285355)](#285355)

<!--- Backport version: 11.0.2 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sorenlouv/backport)

<!--BACKPORT [{"author":{"name":"Aleh
Zasypkin","email":"aleh.zasypkin@elastic.co"},"sourceCommit":{"committedDate":"2026-08-18T17:34:14Z","message":"chore(security,
axios): migrate endpoint scripts to fetch (phase 7) (#285355)\n\n##
Summary\n\nPart of the incremental [axios to native
fetch\nmigration](#266556). Phase
7\ncovers the `@elastic/security-defend-workflows` consumers
in\n`security_solution` and drops their three globs
from\n`AXIOS_LEGACY_CONSUMERS`.\n\n## This also fixes a live
defect\n\nMost of these files used axios only for its error type, but
that is no\nlonger the error they receive. Since #268531 `KbnClient`
rejects with\n`KbnClientRequesterError`, which exposes `status`,
`headers` and\n`cause`, and has no `response`, `request`, `config` or
`toJSON`. The\nremaining reads are dead at runtime, and TypeScript
cannot flag them\nbecause a `catch` parameter is `any`:\n\n| File | Dead
check | Effect today |\n| --- | --- | --- |\n| `blocklists`,
`event_filters`, `host_isolation_exceptions`,\n`trusted_apps` |
`e.response.status !== 409` | `TypeError: Cannot read\nproperties of
undefined`, so the \"list already exists\" path fails on\nevery rerun
instead of being ignored |\n| `index_case.ts` | `error.response?.status
!== 404` then\n`error.request.method` | comparison is always true, then
throws, so\ndeleting an already deleted case fails instead of being
ignored |\n| `endpoint_response_actions.ts` | `error?.response?.status
=== 404` |\nthe documented 404 workaround never runs |\n\nThese now
branch on `status`. The hand built error messages are removed\nbecause
`KbnClientRequesterError.message` already carries the same\ndetail.
Verified against a local server, a 409 produces:\n\n```\n[POST
http://host/api/exception_lists] 409 Conflict --
{\"statusCode\":409,\"message\":\"list id already exists\"}\n```\n\n##
Rename\n\n`format_axios_error.ts` no longer has anything to do with
axios, so it\nbecomes `format_http_error.ts`, with `FormattedAxiosError`
to\n`FormattedHttpError` and `catchAxiosErrorFormatAndThrow`
to\n`catchHttpErrorFormatAndThrow`, across its 16
importers.\n`response.status` is kept because callers branch on it.
`request`,\n`response.data` and `response.statusText` are dropped,
having no\nreaders. Detection switches from `instanceof AxiosError` to a
`status`\ncheck.\n\nNote the identically named helper exported
from\n`@kbn/securitysolution-utils` is a separate copy that still uses
axios\nand is scheduled for a later phase, so the two files importing
that one\nare deliberately untouched.\n\n## Other changes\n\n-
`fleet_services.ts` converts its three unauthenticated artifacts
API\nrequests to inline `fetch` calls. Its
other\n`catchHttpErrorFormatAndThrow` calls wrap `KbnClient` requests
and are\nunchanged.\n- `sentinelone_host/common.ts` replaces
`axios.request` with `fetch`.\nOnly `url` and `params` were ever passed,
so the config type narrows to\nthose, with params stringified into
`URLSearchParams`. The retry wrapper\nis unchanged.\n-
`trusted_apps/index.ts` and `endpoint_response_actions.ts` do
not\nimport axios, so no later phase would have covered them. They
are\nincluded because they carry the same defect as their
siblings.\n\n## eslint allowlist\n\nRemoves the
`common/endpoint/data_loaders/**`,\n`common/endpoint/format_axios_error.ts`
and `scripts/endpoint/**` globs.\n9.4, 9.5 and 8.19 have no other axios
importers under those paths, so\nthe backports need no per branch glob
changes. `AXIOS_LEGACY_CONSUMERS`\nnow covers all 249 remaining
consumers exactly, with no unused globs.\n\n## Testing\n\n- `node
scripts/eslint` clean, and the global axios ban confirmed to\nfire on
the migrated files once the globs were removed.\n- `node
scripts/type_check
--project\nx-pack/solutions/security/plugins/security_solution/tsconfig.json`\npasses.\n-
`node scripts/check_changes.ts` passes.\n- Verified `KbnClient`'s error
shape against a local server: `status` is\nset, `response` / `request` /
`toJSON` are absent, and the message\ncarries method, url, status and
body.\n- Exercised `S1Client` and the error helper against a mock
server: query\nserialization including boolean and numeric params, the
`APIToken`\nparameter, package parsing, download url construction,
non-2xx rejection\ncarrying status, status text and body, and the
helper's three branches.\n\n## Backport note\n\n`fleet_services.ts`
diverges on the release branches (44 lines on 9.5,\n234 on 9.4, 801 on
8.19), so that hunk will need to be re-aimed\nmanually. The other files
are identical to main on 9.4 and 9.5, and\nwithin 10 lines on
8.19.\n\n---------\n\nCo-authored-by: Claude Opus 4.7
<noreply@anthropic.com>","sha":"601e0dd0208a23c6ab398c20e9da41881d75ea8e","branchLabelMapping":{"^v9.6.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["chore","release_note:skip","Team:Defend
Workflows","backport:all-open","v9.6.0"],"title":"chore(security,
axios): migrate endpoint scripts to fetch (phase
7)","number":285355,"url":"https://github.com/elastic/kibana/pull/285355","mergeCommit":{"message":"chore(security,
axios): migrate endpoint scripts to fetch (phase 7) (#285355)\n\n##
Summary\n\nPart of the incremental [axios to native
fetch\nmigration](#266556). Phase
7\ncovers the `@elastic/security-defend-workflows` consumers
in\n`security_solution` and drops their three globs
from\n`AXIOS_LEGACY_CONSUMERS`.\n\n## This also fixes a live
defect\n\nMost of these files used axios only for its error type, but
that is no\nlonger the error they receive. Since #268531 `KbnClient`
rejects with\n`KbnClientRequesterError`, which exposes `status`,
`headers` and\n`cause`, and has no `response`, `request`, `config` or
`toJSON`. The\nremaining reads are dead at runtime, and TypeScript
cannot flag them\nbecause a `catch` parameter is `any`:\n\n| File | Dead
check | Effect today |\n| --- | --- | --- |\n| `blocklists`,
`event_filters`, `host_isolation_exceptions`,\n`trusted_apps` |
`e.response.status !== 409` | `TypeError: Cannot read\nproperties of
undefined`, so the \"list already exists\" path fails on\nevery rerun
instead of being ignored |\n| `index_case.ts` | `error.response?.status
!== 404` then\n`error.request.method` | comparison is always true, then
throws, so\ndeleting an already deleted case fails instead of being
ignored |\n| `endpoint_response_actions.ts` | `error?.response?.status
=== 404` |\nthe documented 404 workaround never runs |\n\nThese now
branch on `status`. The hand built error messages are removed\nbecause
`KbnClientRequesterError.message` already carries the same\ndetail.
Verified against a local server, a 409 produces:\n\n```\n[POST
http://host/api/exception_lists] 409 Conflict --
{\"statusCode\":409,\"message\":\"list id already exists\"}\n```\n\n##
Rename\n\n`format_axios_error.ts` no longer has anything to do with
axios, so it\nbecomes `format_http_error.ts`, with `FormattedAxiosError`
to\n`FormattedHttpError` and `catchAxiosErrorFormatAndThrow`
to\n`catchHttpErrorFormatAndThrow`, across its 16
importers.\n`response.status` is kept because callers branch on it.
`request`,\n`response.data` and `response.statusText` are dropped,
having no\nreaders. Detection switches from `instanceof AxiosError` to a
`status`\ncheck.\n\nNote the identically named helper exported
from\n`@kbn/securitysolution-utils` is a separate copy that still uses
axios\nand is scheduled for a later phase, so the two files importing
that one\nare deliberately untouched.\n\n## Other changes\n\n-
`fleet_services.ts` converts its three unauthenticated artifacts
API\nrequests to inline `fetch` calls. Its
other\n`catchHttpErrorFormatAndThrow` calls wrap `KbnClient` requests
and are\nunchanged.\n- `sentinelone_host/common.ts` replaces
`axios.request` with `fetch`.\nOnly `url` and `params` were ever passed,
so the config type narrows to\nthose, with params stringified into
`URLSearchParams`. The retry wrapper\nis unchanged.\n-
`trusted_apps/index.ts` and `endpoint_response_actions.ts` do
not\nimport axios, so no later phase would have covered them. They
are\nincluded because they carry the same defect as their
siblings.\n\n## eslint allowlist\n\nRemoves the
`common/endpoint/data_loaders/**`,\n`common/endpoint/format_axios_error.ts`
and `scripts/endpoint/**` globs.\n9.4, 9.5 and 8.19 have no other axios
importers under those paths, so\nthe backports need no per branch glob
changes. `AXIOS_LEGACY_CONSUMERS`\nnow covers all 249 remaining
consumers exactly, with no unused globs.\n\n## Testing\n\n- `node
scripts/eslint` clean, and the global axios ban confirmed to\nfire on
the migrated files once the globs were removed.\n- `node
scripts/type_check
--project\nx-pack/solutions/security/plugins/security_solution/tsconfig.json`\npasses.\n-
`node scripts/check_changes.ts` passes.\n- Verified `KbnClient`'s error
shape against a local server: `status` is\nset, `response` / `request` /
`toJSON` are absent, and the message\ncarries method, url, status and
body.\n- Exercised `S1Client` and the error helper against a mock
server: query\nserialization including boolean and numeric params, the
`APIToken`\nparameter, package parsing, download url construction,
non-2xx rejection\ncarrying status, status text and body, and the
helper's three branches.\n\n## Backport note\n\n`fleet_services.ts`
diverges on the release branches (44 lines on 9.5,\n234 on 9.4, 801 on
8.19), so that hunk will need to be re-aimed\nmanually. The other files
are identical to main on 9.4 and 9.5, and\nwithin 10 lines on
8.19.\n\n---------\n\nCo-authored-by: Claude Opus 4.7
<noreply@anthropic.com>","sha":"601e0dd0208a23c6ab398c20e9da41881d75ea8e"}},"sourceBranch":"main","suggestedTargetBranches":[],"targetPullRequestStates":[{"branch":"main","label":"v9.6.0","branchLabelMappingKey":"^v9.6.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/285355","number":285355,"mergeCommit":{"message":"chore(security,
axios): migrate endpoint scripts to fetch (phase 7) (#285355)\n\n##
Summary\n\nPart of the incremental [axios to native
fetch\nmigration](#266556). Phase
7\ncovers the `@elastic/security-defend-workflows` consumers
in\n`security_solution` and drops their three globs
from\n`AXIOS_LEGACY_CONSUMERS`.\n\n## This also fixes a live
defect\n\nMost of these files used axios only for its error type, but
that is no\nlonger the error they receive. Since #268531 `KbnClient`
rejects with\n`KbnClientRequesterError`, which exposes `status`,
`headers` and\n`cause`, and has no `response`, `request`, `config` or
`toJSON`. The\nremaining reads are dead at runtime, and TypeScript
cannot flag them\nbecause a `catch` parameter is `any`:\n\n| File | Dead
check | Effect today |\n| --- | --- | --- |\n| `blocklists`,
`event_filters`, `host_isolation_exceptions`,\n`trusted_apps` |
`e.response.status !== 409` | `TypeError: Cannot read\nproperties of
undefined`, so the \"list already exists\" path fails on\nevery rerun
instead of being ignored |\n| `index_case.ts` | `error.response?.status
!== 404` then\n`error.request.method` | comparison is always true, then
throws, so\ndeleting an already deleted case fails instead of being
ignored |\n| `endpoint_response_actions.ts` | `error?.response?.status
=== 404` |\nthe documented 404 workaround never runs |\n\nThese now
branch on `status`. The hand built error messages are removed\nbecause
`KbnClientRequesterError.message` already carries the same\ndetail.
Verified against a local server, a 409 produces:\n\n```\n[POST
http://host/api/exception_lists] 409 Conflict --
{\"statusCode\":409,\"message\":\"list id already exists\"}\n```\n\n##
Rename\n\n`format_axios_error.ts` no longer has anything to do with
axios, so it\nbecomes `format_http_error.ts`, with `FormattedAxiosError`
to\n`FormattedHttpError` and `catchAxiosErrorFormatAndThrow`
to\n`catchHttpErrorFormatAndThrow`, across its 16
importers.\n`response.status` is kept because callers branch on it.
`request`,\n`response.data` and `response.statusText` are dropped,
having no\nreaders. Detection switches from `instanceof AxiosError` to a
`status`\ncheck.\n\nNote the identically named helper exported
from\n`@kbn/securitysolution-utils` is a separate copy that still uses
axios\nand is scheduled for a later phase, so the two files importing
that one\nare deliberately untouched.\n\n## Other changes\n\n-
`fleet_services.ts` converts its three unauthenticated artifacts
API\nrequests to inline `fetch` calls. Its
other\n`catchHttpErrorFormatAndThrow` calls wrap `KbnClient` requests
and are\nunchanged.\n- `sentinelone_host/common.ts` replaces
`axios.request` with `fetch`.\nOnly `url` and `params` were ever passed,
so the config type narrows to\nthose, with params stringified into
`URLSearchParams`. The retry wrapper\nis unchanged.\n-
`trusted_apps/index.ts` and `endpoint_response_actions.ts` do
not\nimport axios, so no later phase would have covered them. They
are\nincluded because they carry the same defect as their
siblings.\n\n## eslint allowlist\n\nRemoves the
`common/endpoint/data_loaders/**`,\n`common/endpoint/format_axios_error.ts`
and `scripts/endpoint/**` globs.\n9.4, 9.5 and 8.19 have no other axios
importers under those paths, so\nthe backports need no per branch glob
changes. `AXIOS_LEGACY_CONSUMERS`\nnow covers all 249 remaining
consumers exactly, with no unused globs.\n\n## Testing\n\n- `node
scripts/eslint` clean, and the global axios ban confirmed to\nfire on
the migrated files once the globs were removed.\n- `node
scripts/type_check
--project\nx-pack/solutions/security/plugins/security_solution/tsconfig.json`\npasses.\n-
`node scripts/check_changes.ts` passes.\n- Verified `KbnClient`'s error
shape against a local server: `status` is\nset, `response` / `request` /
`toJSON` are absent, and the message\ncarries method, url, status and
body.\n- Exercised `S1Client` and the error helper against a mock
server: query\nserialization including boolean and numeric params, the
`APIToken`\nparameter, package parsing, download url construction,
non-2xx rejection\ncarrying status, status text and body, and the
helper's three branches.\n\n## Backport note\n\n`fleet_services.ts`
diverges on the release branches (44 lines on 9.5,\n234 on 9.4, 801 on
8.19), so that hunk will need to be re-aimed\nmanually. The other files
are identical to main on 9.4 and 9.5, and\nwithin 10 lines on
8.19.\n\n---------\n\nCo-authored-by: Claude Opus 4.7
<noreply@anthropic.com>","sha":"601e0dd0208a23c6ab398c20e9da41881d75ea8e"}}]}]
BACKPORT-->
azasypkin added a commit that referenced this pull request Aug 19, 2026
…se 7) (#285355) (#285960)

# Backport

This will backport the following commits from `main` to `8.19`:
- [chore(security, axios): migrate endpoint scripts to fetch (phase 7)
(#285355)](#285355)

<!--- Backport version: 11.0.2 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sorenlouv/backport)

<!--BACKPORT [{"author":{"name":"Aleh
Zasypkin","email":"aleh.zasypkin@elastic.co"},"sourceCommit":{"committedDate":"2026-08-18T17:34:14Z","message":"chore(security,
axios): migrate endpoint scripts to fetch (phase 7) (#285355)\n\n##
Summary\n\nPart of the incremental [axios to native
fetch\nmigration](#266556). Phase
7\ncovers the `@elastic/security-defend-workflows` consumers
in\n`security_solution` and drops their three globs
from\n`AXIOS_LEGACY_CONSUMERS`.\n\n## This also fixes a live
defect\n\nMost of these files used axios only for its error type, but
that is no\nlonger the error they receive. Since #268531 `KbnClient`
rejects with\n`KbnClientRequesterError`, which exposes `status`,
`headers` and\n`cause`, and has no `response`, `request`, `config` or
`toJSON`. The\nremaining reads are dead at runtime, and TypeScript
cannot flag them\nbecause a `catch` parameter is `any`:\n\n| File | Dead
check | Effect today |\n| --- | --- | --- |\n| `blocklists`,
`event_filters`, `host_isolation_exceptions`,\n`trusted_apps` |
`e.response.status !== 409` | `TypeError: Cannot read\nproperties of
undefined`, so the \"list already exists\" path fails on\nevery rerun
instead of being ignored |\n| `index_case.ts` | `error.response?.status
!== 404` then\n`error.request.method` | comparison is always true, then
throws, so\ndeleting an already deleted case fails instead of being
ignored |\n| `endpoint_response_actions.ts` | `error?.response?.status
=== 404` |\nthe documented 404 workaround never runs |\n\nThese now
branch on `status`. The hand built error messages are removed\nbecause
`KbnClientRequesterError.message` already carries the same\ndetail.
Verified against a local server, a 409 produces:\n\n```\n[POST
http://host/api/exception_lists] 409 Conflict --
{\"statusCode\":409,\"message\":\"list id already exists\"}\n```\n\n##
Rename\n\n`format_axios_error.ts` no longer has anything to do with
axios, so it\nbecomes `format_http_error.ts`, with `FormattedAxiosError`
to\n`FormattedHttpError` and `catchAxiosErrorFormatAndThrow`
to\n`catchHttpErrorFormatAndThrow`, across its 16
importers.\n`response.status` is kept because callers branch on it.
`request`,\n`response.data` and `response.statusText` are dropped,
having no\nreaders. Detection switches from `instanceof AxiosError` to a
`status`\ncheck.\n\nNote the identically named helper exported
from\n`@kbn/securitysolution-utils` is a separate copy that still uses
axios\nand is scheduled for a later phase, so the two files importing
that one\nare deliberately untouched.\n\n## Other changes\n\n-
`fleet_services.ts` converts its three unauthenticated artifacts
API\nrequests to inline `fetch` calls. Its
other\n`catchHttpErrorFormatAndThrow` calls wrap `KbnClient` requests
and are\nunchanged.\n- `sentinelone_host/common.ts` replaces
`axios.request` with `fetch`.\nOnly `url` and `params` were ever passed,
so the config type narrows to\nthose, with params stringified into
`URLSearchParams`. The retry wrapper\nis unchanged.\n-
`trusted_apps/index.ts` and `endpoint_response_actions.ts` do
not\nimport axios, so no later phase would have covered them. They
are\nincluded because they carry the same defect as their
siblings.\n\n## eslint allowlist\n\nRemoves the
`common/endpoint/data_loaders/**`,\n`common/endpoint/format_axios_error.ts`
and `scripts/endpoint/**` globs.\n9.4, 9.5 and 8.19 have no other axios
importers under those paths, so\nthe backports need no per branch glob
changes. `AXIOS_LEGACY_CONSUMERS`\nnow covers all 249 remaining
consumers exactly, with no unused globs.\n\n## Testing\n\n- `node
scripts/eslint` clean, and the global axios ban confirmed to\nfire on
the migrated files once the globs were removed.\n- `node
scripts/type_check
--project\nx-pack/solutions/security/plugins/security_solution/tsconfig.json`\npasses.\n-
`node scripts/check_changes.ts` passes.\n- Verified `KbnClient`'s error
shape against a local server: `status` is\nset, `response` / `request` /
`toJSON` are absent, and the message\ncarries method, url, status and
body.\n- Exercised `S1Client` and the error helper against a mock
server: query\nserialization including boolean and numeric params, the
`APIToken`\nparameter, package parsing, download url construction,
non-2xx rejection\ncarrying status, status text and body, and the
helper's three branches.\n\n## Backport note\n\n`fleet_services.ts`
diverges on the release branches (44 lines on 9.5,\n234 on 9.4, 801 on
8.19), so that hunk will need to be re-aimed\nmanually. The other files
are identical to main on 9.4 and 9.5, and\nwithin 10 lines on
8.19.\n\n---------\n\nCo-authored-by: Claude Opus 4.7
<noreply@anthropic.com>","sha":"601e0dd0208a23c6ab398c20e9da41881d75ea8e","branchLabelMapping":{"^v9.6.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["chore","release_note:skip","Team:Defend
Workflows","backport:all-open","v9.6.0"],"title":"chore(security,
axios): migrate endpoint scripts to fetch (phase
7)","number":285355,"url":"https://github.com/elastic/kibana/pull/285355","mergeCommit":{"message":"chore(security,
axios): migrate endpoint scripts to fetch (phase 7) (#285355)\n\n##
Summary\n\nPart of the incremental [axios to native
fetch\nmigration](#266556). Phase
7\ncovers the `@elastic/security-defend-workflows` consumers
in\n`security_solution` and drops their three globs
from\n`AXIOS_LEGACY_CONSUMERS`.\n\n## This also fixes a live
defect\n\nMost of these files used axios only for its error type, but
that is no\nlonger the error they receive. Since #268531 `KbnClient`
rejects with\n`KbnClientRequesterError`, which exposes `status`,
`headers` and\n`cause`, and has no `response`, `request`, `config` or
`toJSON`. The\nremaining reads are dead at runtime, and TypeScript
cannot flag them\nbecause a `catch` parameter is `any`:\n\n| File | Dead
check | Effect today |\n| --- | --- | --- |\n| `blocklists`,
`event_filters`, `host_isolation_exceptions`,\n`trusted_apps` |
`e.response.status !== 409` | `TypeError: Cannot read\nproperties of
undefined`, so the \"list already exists\" path fails on\nevery rerun
instead of being ignored |\n| `index_case.ts` | `error.response?.status
!== 404` then\n`error.request.method` | comparison is always true, then
throws, so\ndeleting an already deleted case fails instead of being
ignored |\n| `endpoint_response_actions.ts` | `error?.response?.status
=== 404` |\nthe documented 404 workaround never runs |\n\nThese now
branch on `status`. The hand built error messages are removed\nbecause
`KbnClientRequesterError.message` already carries the same\ndetail.
Verified against a local server, a 409 produces:\n\n```\n[POST
http://host/api/exception_lists] 409 Conflict --
{\"statusCode\":409,\"message\":\"list id already exists\"}\n```\n\n##
Rename\n\n`format_axios_error.ts` no longer has anything to do with
axios, so it\nbecomes `format_http_error.ts`, with `FormattedAxiosError`
to\n`FormattedHttpError` and `catchAxiosErrorFormatAndThrow`
to\n`catchHttpErrorFormatAndThrow`, across its 16
importers.\n`response.status` is kept because callers branch on it.
`request`,\n`response.data` and `response.statusText` are dropped,
having no\nreaders. Detection switches from `instanceof AxiosError` to a
`status`\ncheck.\n\nNote the identically named helper exported
from\n`@kbn/securitysolution-utils` is a separate copy that still uses
axios\nand is scheduled for a later phase, so the two files importing
that one\nare deliberately untouched.\n\n## Other changes\n\n-
`fleet_services.ts` converts its three unauthenticated artifacts
API\nrequests to inline `fetch` calls. Its
other\n`catchHttpErrorFormatAndThrow` calls wrap `KbnClient` requests
and are\nunchanged.\n- `sentinelone_host/common.ts` replaces
`axios.request` with `fetch`.\nOnly `url` and `params` were ever passed,
so the config type narrows to\nthose, with params stringified into
`URLSearchParams`. The retry wrapper\nis unchanged.\n-
`trusted_apps/index.ts` and `endpoint_response_actions.ts` do
not\nimport axios, so no later phase would have covered them. They
are\nincluded because they carry the same defect as their
siblings.\n\n## eslint allowlist\n\nRemoves the
`common/endpoint/data_loaders/**`,\n`common/endpoint/format_axios_error.ts`
and `scripts/endpoint/**` globs.\n9.4, 9.5 and 8.19 have no other axios
importers under those paths, so\nthe backports need no per branch glob
changes. `AXIOS_LEGACY_CONSUMERS`\nnow covers all 249 remaining
consumers exactly, with no unused globs.\n\n## Testing\n\n- `node
scripts/eslint` clean, and the global axios ban confirmed to\nfire on
the migrated files once the globs were removed.\n- `node
scripts/type_check
--project\nx-pack/solutions/security/plugins/security_solution/tsconfig.json`\npasses.\n-
`node scripts/check_changes.ts` passes.\n- Verified `KbnClient`'s error
shape against a local server: `status` is\nset, `response` / `request` /
`toJSON` are absent, and the message\ncarries method, url, status and
body.\n- Exercised `S1Client` and the error helper against a mock
server: query\nserialization including boolean and numeric params, the
`APIToken`\nparameter, package parsing, download url construction,
non-2xx rejection\ncarrying status, status text and body, and the
helper's three branches.\n\n## Backport note\n\n`fleet_services.ts`
diverges on the release branches (44 lines on 9.5,\n234 on 9.4, 801 on
8.19), so that hunk will need to be re-aimed\nmanually. The other files
are identical to main on 9.4 and 9.5, and\nwithin 10 lines on
8.19.\n\n---------\n\nCo-authored-by: Claude Opus 4.7
<noreply@anthropic.com>","sha":"601e0dd0208a23c6ab398c20e9da41881d75ea8e"}},"sourceBranch":"main","suggestedTargetBranches":[],"targetPullRequestStates":[{"branch":"main","label":"v9.6.0","branchLabelMappingKey":"^v9.6.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/285355","number":285355,"mergeCommit":{"message":"chore(security,
axios): migrate endpoint scripts to fetch (phase 7) (#285355)\n\n##
Summary\n\nPart of the incremental [axios to native
fetch\nmigration](#266556). Phase
7\ncovers the `@elastic/security-defend-workflows` consumers
in\n`security_solution` and drops their three globs
from\n`AXIOS_LEGACY_CONSUMERS`.\n\n## This also fixes a live
defect\n\nMost of these files used axios only for its error type, but
that is no\nlonger the error they receive. Since #268531 `KbnClient`
rejects with\n`KbnClientRequesterError`, which exposes `status`,
`headers` and\n`cause`, and has no `response`, `request`, `config` or
`toJSON`. The\nremaining reads are dead at runtime, and TypeScript
cannot flag them\nbecause a `catch` parameter is `any`:\n\n| File | Dead
check | Effect today |\n| --- | --- | --- |\n| `blocklists`,
`event_filters`, `host_isolation_exceptions`,\n`trusted_apps` |
`e.response.status !== 409` | `TypeError: Cannot read\nproperties of
undefined`, so the \"list already exists\" path fails on\nevery rerun
instead of being ignored |\n| `index_case.ts` | `error.response?.status
!== 404` then\n`error.request.method` | comparison is always true, then
throws, so\ndeleting an already deleted case fails instead of being
ignored |\n| `endpoint_response_actions.ts` | `error?.response?.status
=== 404` |\nthe documented 404 workaround never runs |\n\nThese now
branch on `status`. The hand built error messages are removed\nbecause
`KbnClientRequesterError.message` already carries the same\ndetail.
Verified against a local server, a 409 produces:\n\n```\n[POST
http://host/api/exception_lists] 409 Conflict --
{\"statusCode\":409,\"message\":\"list id already exists\"}\n```\n\n##
Rename\n\n`format_axios_error.ts` no longer has anything to do with
axios, so it\nbecomes `format_http_error.ts`, with `FormattedAxiosError`
to\n`FormattedHttpError` and `catchAxiosErrorFormatAndThrow`
to\n`catchHttpErrorFormatAndThrow`, across its 16
importers.\n`response.status` is kept because callers branch on it.
`request`,\n`response.data` and `response.statusText` are dropped,
having no\nreaders. Detection switches from `instanceof AxiosError` to a
`status`\ncheck.\n\nNote the identically named helper exported
from\n`@kbn/securitysolution-utils` is a separate copy that still uses
axios\nand is scheduled for a later phase, so the two files importing
that one\nare deliberately untouched.\n\n## Other changes\n\n-
`fleet_services.ts` converts its three unauthenticated artifacts
API\nrequests to inline `fetch` calls. Its
other\n`catchHttpErrorFormatAndThrow` calls wrap `KbnClient` requests
and are\nunchanged.\n- `sentinelone_host/common.ts` replaces
`axios.request` with `fetch`.\nOnly `url` and `params` were ever passed,
so the config type narrows to\nthose, with params stringified into
`URLSearchParams`. The retry wrapper\nis unchanged.\n-
`trusted_apps/index.ts` and `endpoint_response_actions.ts` do
not\nimport axios, so no later phase would have covered them. They
are\nincluded because they carry the same defect as their
siblings.\n\n## eslint allowlist\n\nRemoves the
`common/endpoint/data_loaders/**`,\n`common/endpoint/format_axios_error.ts`
and `scripts/endpoint/**` globs.\n9.4, 9.5 and 8.19 have no other axios
importers under those paths, so\nthe backports need no per branch glob
changes. `AXIOS_LEGACY_CONSUMERS`\nnow covers all 249 remaining
consumers exactly, with no unused globs.\n\n## Testing\n\n- `node
scripts/eslint` clean, and the global axios ban confirmed to\nfire on
the migrated files once the globs were removed.\n- `node
scripts/type_check
--project\nx-pack/solutions/security/plugins/security_solution/tsconfig.json`\npasses.\n-
`node scripts/check_changes.ts` passes.\n- Verified `KbnClient`'s error
shape against a local server: `status` is\nset, `response` / `request` /
`toJSON` are absent, and the message\ncarries method, url, status and
body.\n- Exercised `S1Client` and the error helper against a mock
server: query\nserialization including boolean and numeric params, the
`APIToken`\nparameter, package parsing, download url construction,
non-2xx rejection\ncarrying status, status text and body, and the
helper's three branches.\n\n## Backport note\n\n`fleet_services.ts`
diverges on the release branches (44 lines on 9.5,\n234 on 9.4, 801 on
8.19), so that hunk will need to be re-aimed\nmanually. The other files
are identical to main on 9.4 and 9.5, and\nwithin 10 lines on
8.19.\n\n---------\n\nCo-authored-by: Claude Opus 4.7
<noreply@anthropic.com>","sha":"601e0dd0208a23c6ab398c20e9da41881d75ea8e"}}]}]
BACKPORT-->

Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport:all-open Backport to all branches that could still receive a release chore ci:all-cypress-suites ci:project-deploy-observability Create an Observability project release_note:skip Skip the PR/issue when compiling release notes Team:Fleet - DEPRECATED Use Team:streams-ui Team:obs-presentation Focus: APM UI, Infra UI, Hosts UI, Universal Profiling, Obs Overview and left Navigation v8.19.16 v9.3.5 v9.4.2 v9.5.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.