# \[8.3.2\] Message at Kibana's login page "Please upgrade your browser" when applying a Tampermonkey userscript

**URL:** <https://discuss.elastic.co/t/8-3-2-message-at-kibanas-login-page-please-upgrade-your-browser-when-applying-a-tampermonkey-userscript/309796>\
**Category:** Kibana\
**Created:** [July 16, 2022, 3:54pm UTC](https://discuss.elastic.co/t/8-3-2-message-at-kibanas-login-page-please-upgrade-your-browser-when-applying-a-tampermonkey-userscript/309796 "2022-07-16T15:54:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gerib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerib/32/106584_2.png) [@gerib](https://discuss.elastic.co/u/gerib)\
**Post date:** [July 16, 2022, 3:54pm UTC](https://discuss.elastic.co/t/8-3-2-message-at-kibanas-login-page-please-upgrade-your-browser-when-applying-a-tampermonkey-userscript/309796/1 "2022-07-16T15:54:44Z")

</div>

When applying the following userscript in Tampermonkey:

```auto
// ==UserScript==
// @name tab-size: 2
// @description Sets the tab (U+9) character's display size to 2.
// @version 22.07.16-1645
// @author Gerold 'Geri' Broser <https://stackoverflow.com/users/1744774>
// @namespace igb
// @match http://*/*
// @match https://*/*
// @grant none
// ==/UserScript==

(function() {
  'use strict';

    try {
        console.log("BEGIN tab-size: 2...");

        let body = document.getElementsByTagName("body")[0]
        body.style.tabSize = 2

        console.log("END tab-size: 2.")
    }
	catch (e) {
		console.error(e)
	}

})();

```

Kibana's login page shows:

> **Please upgrade your browser**
> 
> This Elastic installation has strict security requirements enabled that your current browser does not meet.

WT...H?

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [July 19, 2022, 7:27am UTC](https://discuss.elastic.co/t/8-3-2-message-at-kibanas-login-page-please-upgrade-your-browser-when-applying-a-tampermonkey-userscript/309796/2 "2022-07-19T07:27:46Z")

</div>

To improve security, Kibana has a CSP configured: [Content Security Policy (CSP) - HTTP | MDN](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP)

It seems like this can throw off tampermonkey scripts - see this stackoverflow question which looks like it's related: [javascript - Tampermonkey script blocked by a CSP error - Stack Overflow](https://stackoverflow.com/questions/69786354/tampermonkey-script-blocked-by-a-csp-error)

---

<div class="post-metadata">

**Author:** ![gerib](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerib/32/106584_2.png) [@gerib](https://discuss.elastic.co/u/gerib)\
**Post date:** [July 19, 2022, 10:51am UTC](https://discuss.elastic.co/t/8-3-2-message-at-kibanas-login-page-please-upgrade-your-browser-when-applying-a-tampermonkey-userscript/309796/3 "2022-07-19T10:51:49Z")

</div>

Thanks for the SO link, but it even doesn't work with:

```auto
...
// @grant GM_addStyle
...
GM_addStyle('body { tab-size: 2 !important; }')
...

```

I solved it with:

```auto
...
// @exclude https://*kibana*
...

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 16, 2022, 10:52am UTC](https://discuss.elastic.co/t/8-3-2-message-at-kibanas-login-page-please-upgrade-your-browser-when-applying-a-tampermonkey-userscript/309796/4 "2022-08-16T10:52:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
