# Authenticating to iframe-embedded Kibana dashboard

**URL:** <https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129>\
**Category:** Kibana\
**Created:** [January 10, 2017, 5:52pm UTC](https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129 "2017-01-10T17:52:45Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![rupaln](https://avatars.discourse-cdn.com/v4/letter/r/97f17d/32.png) [@rupaln](https://discuss.elastic.co/u/rupaln)\
**Post date:** [January 10, 2017, 5:52pm UTC](https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129/1 "2017-01-10T17:52:45Z")

</div>

Hi,  
We have shield protected kibana dashboard embedded as iframe in our UI. We need to be able to pass authentication headers to the dashboard so that the reports can display without the user having to put credentials again. How can we pass the auth headers to kibana from UI?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 10, 2017, 8:57pm UTC](https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129/2 "2017-01-10T20:57:12Z")

</div>

Hi @rupaln,

please take a look at this [previous thread](https://discuss.elastic.co/t/auto-authenticating-to-iframe-embedded-kibana-dashboard/46091). The suggestions made therein still appear to be valid.

---

<div class="post-metadata">

**Author:** ![rupaln](https://avatars.discourse-cdn.com/v4/letter/r/97f17d/32.png) [@rupaln](https://discuss.elastic.co/u/rupaln)\
**Post date:** [January 10, 2017, 10:22pm UTC](https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129/3 "2017-01-10T22:22:56Z")

</div>

We do have a nginx proxy but can not hard code the basic-auth header as it is in cloud environment. Is there any way we can pass the authorization header with each request to kibana.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 11, 2017, 11:43am UTC](https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129/4 "2017-01-11T11:43:58Z")

</div>

In that case you will have to rely on the browser to add the header. Some browser do that when the url contains credentials as in `https://user:password@my-kiba.na`, but not all browsers do that due to the inherent security problems. You could also try to perform a pre-flight ajax request to Kibana from JavaScript code on the page containing the iframe. There you should be able to pass authentication headers and thus let Kibana set a session cookie for the domain. This cookie should then be recognized by subsequent requests to Kibana. In order to permit the request from JavaScript code though you would have add CORS headers to your Kibana responses or proxy it through the same host the embedding page is served from.

---

<div class="post-metadata">

**Author:** ![rupaln](https://avatars.discourse-cdn.com/v4/letter/r/97f17d/32.png) [@rupaln](https://discuss.elastic.co/u/rupaln)\
**Post date:** [January 12, 2017, 12:36am UTC](https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129/5 "2017-01-12T00:36:38Z")

</div>

Thanks. Will give it a try.

---

<div class="post-metadata">

**Author:** ![rupaln](https://avatars.discourse-cdn.com/v4/letter/r/97f17d/32.png) [@rupaln](https://discuss.elastic.co/u/rupaln)\
**Post date:** [January 12, 2017, 10:23pm UTC](https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129/6 "2017-01-12T22:23:13Z")

</div>

We tried preforming pre-flight ajax request with authentication headers but do not see the cookie getting created. Is there any configuration setting that we have to enable?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 23, 2017, 11:50am UTC](https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129/7 "2017-01-23T11:50:46Z")

</div>

Sorry for the delay, @rupaln and sorry for giving incomplete advice.

I was able to get the Kibana server to respond with a cookie header by POSTing to `/api/security/v1/login` with a JSON request body of

```
{
    "password": "<YOURPASSWORD>",
    "username": "<YOURUSERNAME>"
}

```

and the appropriate `kbn-version: 5.1.1` header.

---

<div class="post-metadata">

**Author:** ![rupaln](https://avatars.discourse-cdn.com/v4/letter/r/97f17d/32.png) [@rupaln](https://discuss.elastic.co/u/rupaln)\
**Post date:** [January 23, 2017, 8:46pm UTC](https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129/8 "2017-01-23T20:46:39Z")

</div>

We are using kibana version 4.6.1. When I tried posting to /api/security/v1/login, I got 404.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 24, 2017, 9:57am UTC](https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129/9 "2017-01-24T09:57:44Z")

</div>

Sorry, about that - I'm mostly living in a 5.x world by now and i would recommend everyone to upgrade 😉 You might be able to achieve the same thing using `/api/shield/v1/login` instead on Kibana 4.x + Shield 2.x.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2017, 9:57am UTC](https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129/10 "2017-02-21T09:57:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
