# Authenticate on Kibana 6.0.0 with a post

**URL:** <https://discuss.elastic.co/t/authenticate-on-kibana-6-0-0-with-a-post/109725>\
**Category:** Kibana\
**Created:** [November 30, 2017, 10:08am UTC](https://discuss.elastic.co/t/authenticate-on-kibana-6-0-0-with-a-post/109725 "2017-11-30T10:08:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![JulienC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julienc/32/24865_2.png) [@JulienC](https://discuss.elastic.co/u/JulienC)\
**Post date:** [November 30, 2017, 10:08am UTC](https://discuss.elastic.co/t/authenticate-on-kibana-6-0-0-with-a-post/109725/1 "2017-11-30T10:08:34Z")

</div>

Hello,

I would like to add an iframe targeting Kibana with authentication.

With the help of this thread ([Authenticating to iframe-embedded Kibana dashboard](https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129/7) ), I added a POST to handle authentication before loading the iFrame.

But the POST fails on the preflight OPTIONS call when the header 'kbn-version' is present.  
And if I remove the 'kbn-version' the OPTIONS call is successful but the subsequent POST fails because the 'kbn-version' header is not present.

How I can make this scenario work ?

Your help is greatly appreciated.  
Julien

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [December 5, 2017, 10:40am UTC](https://discuss.elastic.co/t/authenticate-on-kibana-6-0-0-with-a-post/109725/2 "2017-12-05T10:40:28Z")

</div>

Hi @JulienC,

I was unable to reproduce the problem. Could you please provide a detailed description of the request with all headers?

---

<div class="post-metadata">

**Author:** ![JulienC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julienc/32/24865_2.png) [@JulienC](https://discuss.elastic.co/u/JulienC)\
**Post date:** [December 5, 2017, 1:16pm UTC](https://discuss.elastic.co/t/authenticate-on-kibana-6-0-0-with-a-post/109725/3 "2017-12-05T13:16:11Z")

</div>

Hi @weltenwort,

To test the scenario above, I have add one line in the kibana.yml:  
server.cors: true

My website which host the iframe make a POST on the login API (/api/security/v1/login) with headers:

```
{
    'kbn-version': '6.0.0',
    'Content-Type': 'appliation/json'
}

```

Due to the cross domain, the browser makes a OPTION on the same API, with the following headers:

```
{
    'Access-Control-Request-Headers': 'content-type,kbn-version',
    'Access-Control-Request-Method': 'POST'
}

```

This OPTION call is in error when 'Access-Control-Request-Headers' contains 'kbn-version'.

I did a search on web server used by Kibana (HAPI JS) and the cors option when the server is set up.  
We can use a full json object for a better customization instead of true or false.

And with a complete configuration I was able to log my user automatically.

```
cors: {
    origin: ['*'],
    headers: ['Accept', 'Authorization', 'Content-Type', 'If-None-Match', 'kbn-version', 'Access-Control-Allow-Credentials'],
    credentials: true
},

```

Is it possible to specify this configuration inside kibana.yml (server.cors allow only boolean) ?  
It would be very usefull to parameter a specific origin domain and more.

Thank you,

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [December 5, 2017, 2:53pm UTC](https://discuss.elastic.co/t/authenticate-on-kibana-6-0-0-with-a-post/109725/4 "2017-12-05T14:53:42Z")

</div>

You're hitting a slightly embarrassing point here. The `server.cors` setting accepts different values depending on whether Kibana runs in development or production mode. In dev mode it accepts a full hapi cors config object like the one you showed, but in production mode it only accepts a boolean.

Since I can not in good conscience recommend running Kibana in production, one solution I can think of (until this inconsistency is changed) would be to use a reverse proxy in front of Kibana to strip out the `kbn-version` entry from the `Access-Control-Request-Headers` list (assuming it still works fine on the `POST`). Another option would be to avoid the cors problem altogether by reverse-proxying Kibana on the same domain as the embedding website.

---

<div class="post-metadata">

**Author:** ![JulienC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julienc/32/24865_2.png) [@JulienC](https://discuss.elastic.co/u/JulienC)\
**Post date:** [December 6, 2017, 9:12am UTC](https://discuss.elastic.co/t/authenticate-on-kibana-6-0-0-with-a-post/109725/5 "2017-12-06T09:12:07Z")

</div>

Hi @weltenwort ,

You say:

> (until this inconsistency is changed)

Is it planned to let us configure the CORS of HAPI with full object in production mode ?  
If yes, have you planned for a specific version or date ?

Where can I found documentation about the `server.cors` configuration for Kibana 6.0 ?

Thanks for your answers.  
Julien

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [December 6, 2017, 10:55am UTC](https://discuss.elastic.co/t/authenticate-on-kibana-6-0-0-with-a-post/109725/6 "2017-12-06T10:55:00Z")

</div>

Sorry, I can't give you any specific roadmap dates. The `server.cors` setting is not documented at the moment since we don't want to expose internals. Running Kibana behind your own reverse proxy and managing headers there would be our recommended approach for now.

---

<div class="post-metadata">

**Author:** ![JulienC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julienc/32/24865_2.png) [@JulienC](https://discuss.elastic.co/u/JulienC)\
**Post date:** [December 6, 2017, 12:48pm UTC](https://discuss.elastic.co/t/authenticate-on-kibana-6-0-0-with-a-post/109725/7 "2017-12-06T12:48:31Z")

</div>

Thanks for your advice.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2018, 12:48pm UTC](https://discuss.elastic.co/t/authenticate-on-kibana-6-0-0-with-a-post/109725/8 "2018-01-03T12:48:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
