# Question about the possibilities of Kibana and code development

**URL:** <https://discuss.elastic.co/t/question-about-the-possibilities-of-kibana-and-code-development/210693>\
**Category:** Kibana\
**Created:** [December 5, 2019, 11:44am UTC](https://discuss.elastic.co/t/question-about-the-possibilities-of-kibana-and-code-development/210693 "2019-12-05T11:44:46Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![ya-tmch](https://avatars.discourse-cdn.com/v4/letter/y/eb9ed0/32.png) [@ya-tmch](https://discuss.elastic.co/u/ya-tmch)\
**Post date:** [December 5, 2019, 11:44am UTC](https://discuss.elastic.co/t/question-about-the-possibilities-of-kibana-and-code-development/210693/1 "2019-12-05T11:44:46Z")

</div>

Hello!  
We have crm for our customers.  
In the kibana there is information about the orders of our customers.  
We want to display the embedded dashboard on a specific page in our crm so that each client sees the graphs only for their orders.  
Plus, some clients must see the orders of other clients.

Question 1. Is it possible to immediately authorize a user in embedded, for example, pass some parameters to a iframe with a dashboard?  
Question 2. Where can I write code that will modify the request in elasticsearch, adding an additional condition for filtering to it? Can I do this through the custom plugin?

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [December 5, 2019, 2:24pm UTC](https://discuss.elastic.co/t/question-about-the-possibilities-of-kibana-and-code-development/210693/2 "2019-12-05T14:24:57Z")

</div>

Hi and welcome to our community! 👋

About 1:  
There's an older discuss article about that, so it's possible:

> [@Authenticating to iframe-embedded Kibana dashboard](https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129):
>
> Hi, We have shield protected kibana dashboard embedded as iframe in our UI. We need to be able to pass authentication headers to the dashboard so that the reports can display without the user having to put credentials again. How can we pass the auth headers to kibana from UI?

About 2:  
Which request do you want to modify?

Thanx and best,  
Matthias

---

<div class="post-metadata">

**Author:** ![ya-tmch](https://avatars.discourse-cdn.com/v4/letter/y/eb9ed0/32.png) [@ya-tmch](https://discuss.elastic.co/u/ya-tmch)\
**Post date:** [December 5, 2019, 2:41pm UTC](https://discuss.elastic.co/t/question-about-the-possibilities-of-kibana-and-code-development/210693/3 "2019-12-05T14:41:40Z")

</div>

Thanks for the help! 🙂

> [@matw](#):
>
> Which request do you want to modify?

All requests for data for the graphs.

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [December 6, 2019, 6:47am UTC](https://discuss.elastic.co/t/question-about-the-possibilities-of-kibana-and-code-development/210693/4 "2019-12-06T06:47:25Z")

</div>

If you want to add additional filtering to it you can add it via url. If you add a filter in dashboard, the url is modified. Of course you can also add a filter via url manually.  
Best,  
Matthias

---

<div class="post-metadata">

**Author:** ![ya-tmch](https://avatars.discourse-cdn.com/v4/letter/y/eb9ed0/32.png) [@ya-tmch](https://discuss.elastic.co/u/ya-tmch)\
**Post date:** [December 6, 2019, 8:16am UTC](https://discuss.elastic.co/t/question-about-the-possibilities-of-kibana-and-code-development/210693/5 "2019-12-06T08:16:19Z")

</div>

If you add filtering via URL, then the user will be able to change it.

I had such an idea:

1. In elasticsearch there is a customer\_id field;

2. In the iframe in the URL, I add a parameter, for example, current\_customer\_hash, which is generated in our crm;

3. On the kibana's backend, before sending the request to elasticsearch, I get current\_customer\_hash, which I passed to the URL.

4. I make a request to my server [https://crm.myserver.com/api/get\_available\_customers/{{current\_customer\_hash}](https://crm.myserver.com/api/get_available_customers/%7B%7Bcurrent_customer_hash%7D)}, and get an array of allowed customer\_id for current\_customer\_hash. For example, I will get the answer [433, 936, 209];

5. I modify elasticsearch request, add the filter "customer\_id = [433, 936, 209]" there.

---

<div class="post-metadata">

**Author:** ![ya-tmch](https://avatars.discourse-cdn.com/v4/letter/y/eb9ed0/32.png) [@ya-tmch](https://discuss.elastic.co/u/ya-tmch)\
**Post date:** [December 8, 2019, 12:06pm UTC](https://discuss.elastic.co/t/question-about-the-possibilities-of-kibana-and-code-development/210693/6 "2019-12-08T12:06:16Z")

</div>

Is it possible to do as I wrote above?

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [December 9, 2019, 9:21am UTC](https://discuss.elastic.co/t/question-about-the-possibilities-of-kibana-and-code-development/210693/7 "2019-12-09T09:21:44Z")

</div>

Hi  
In theory this should be possible, but you's need to develop an own custom dashboard plugin for that purpose. And there's no way to e.g. add filters to the existing dashboard requests depending on user permission, so you'd need to create an own solution for this (the effort for this is not to underestimate)  
Best,  
Matthias

---

<div class="post-metadata">

**Author:** ![ya-tmch](https://avatars.discourse-cdn.com/v4/letter/y/eb9ed0/32.png) [@ya-tmch](https://discuss.elastic.co/u/ya-tmch)\
**Post date:** [December 9, 2019, 10:32am UTC](https://discuss.elastic.co/t/question-about-the-possibilities-of-kibana-and-code-development/210693/8 "2019-12-09T10:32:01Z")

</div>

Hi. Thanks for the answer.

How can I get acquainted with the internal architecture of the Kibana? Is there any documentation for developers?

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [December 10, 2019, 7:57am UTC](https://discuss.elastic.co/t/question-about-the-possibilities-of-kibana-and-code-development/210693/9 "2019-12-10T07:57:30Z")

</div>

Hi  
this is a possible starting point:  
[https://www.elastic.co/guide/en/kibana/current/plugin-development.html](https://www.elastic.co/guide/en/kibana/current/plugin-development.html)  
and also a good start is taking a look at existing 3rd party plugins at GitHub

> **[fbaligand/kibana-enhanced-table](https://github.com/fbaligand/kibana-enhanced-table)**
>
> Kibana visualization like a Data Table, but with enhanced features like computed columns, filter bar, and “Split Cols” bucket - fbaligand/kibana-enhanced-table

Here's a list of plugins:

> **[robcowart/kibana\_plugins\_list](https://github.com/robcowart/kibana_plugins_list)**
>
> A list of Kibana Plugins. Contribute to robcowart/kibana\_plugins\_list development by creating an account on GitHub.

Note that we're currently in between a big architectural change, so APIs change and should be final when our next major is released

Best,  
Matthias

---

<div class="post-metadata">

**Author:** ![ya-tmch](https://avatars.discourse-cdn.com/v4/letter/y/eb9ed0/32.png) [@ya-tmch](https://discuss.elastic.co/u/ya-tmch)\
**Post date:** [December 10, 2019, 4:44pm UTC](https://discuss.elastic.co/t/question-about-the-possibilities-of-kibana-and-code-development/210693/10 "2019-12-10T16:44:54Z")

</div>

Сan I make my own plugin that will implement custom search strategy, which will be a proxy for the default search strategy?

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [December 11, 2019, 2:11pm UTC](https://discuss.elastic.co/t/question-about-the-possibilities-of-kibana-and-code-development/210693/11 "2019-12-11T14:11:39Z")

</div>

While in theory this is possible, it's very complex, and the API will change a lot. A better approach might be to solve this via the Elastic Search document level security

[https://www.elastic.co/guide/en/elasticsearch/reference/current/document-level-security.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/document-level-security.html)

So you can define roles that grant only read access to documents with e.g. a certain customer\_id

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2020, 2:11pm UTC](https://discuss.elastic.co/t/question-about-the-possibilities-of-kibana-and-code-development/210693/12 "2020-01-08T14:11:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
