# Authentication Using /api/security/v1/login

**URL:** <https://discuss.elastic.co/t/authentication-using-api-security-v1-login/146496>\
**Category:** Elasticsearch\
**Created:** [August 29, 2018, 9:13am UTC](https://discuss.elastic.co/t/authentication-using-api-security-v1-login/146496 "2018-08-29T09:13:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ritwikkaul](https://avatars.discourse-cdn.com/v4/letter/r/839c29/32.png) [@ritwikkaul](https://discuss.elastic.co/u/ritwikkaul)\
**Post date:** [August 29, 2018, 9:13am UTC](https://discuss.elastic.co/t/authentication-using-api-security-v1-login/146496/1 "2018-08-29T09:13:03Z")

</div>

Hi

I am currently trying to make a fetch call so as to get cookie such that user does not need to enter username and password is directly redirected to kibana homepage.  
But I am getting this error -

> Failed to load [http://localhost:5601/kibana/api/security/v1/login:](http://localhost:5601/kibana/api/security/v1/login:) Response to preflight request doesn't pass access control check: No 'Access-Control-Allow-Origin' header is present on the requested resource. Origin '[http://localhost:8000](http://localhost:8000)' is therefore not allowed access. If an opaque response serves your needs, set the request's mode to 'no-cors' to fetch the resource with CORS disabled.  
> index.html:1 Uncaught (in promise) TypeError: Failed to fetch

My elasticsearch.yml -  
xpack.security.enabled : true  
http.cors.enabled: true  
http.cors.allow-origin: "\*"  
http.cors.allow-credentials: true  
http.cors.allow-headers: "X-Requested-With, Content-Type, Content-Length, Authorization"

my kibana.yml -  
server.cors: true  
server.cors.origin: ['\*']

Any help will be appreciated

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2018, 9:13am UTC](https://discuss.elastic.co/t/authentication-using-api-security-v1-login/146496/2 "2018-09-26T09:13:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
