# Auto-authenticate Kibana 5.3 dashboard embedded in iframe

**URL:** <https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059>\
**Category:** Kibana\
**Created:** [May 9, 2017, 10:22am UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059 "2017-05-09T10:22:36Z")\
**Posts on this page:** 17\
**Page:** 2

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [July 4, 2017, 9:33am UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/21 "2017-07-04T09:33:29Z")

</div>

Sorry, @PrabakarKaruppasamy, but I can not reproduce the problem. I performed the following steps:

- download and unpack the Kibana 5.3.3 archive

- set `server.cors: true` in `config/kibana.yml`

- start Kibana using `bin/kibana`

- send the following request to `http://localhost:5601`:

I get the response

```
HTTP/1.1 200 OK
Connection: keep-alive
Date: Tue, 04 Jul 2017 09:24:24 GMT
access-control-allow-headers: Accept,Authorization,Content-Type,If-None-Match
access-control-allow-methods: GET
access-control-allow-origin: http://example.com
access-control-expose-headers: WWW-Authenticate,Server-Authorization
access-control-max-age: 86400
cache-control: no-cache
content-length: 0
kbn-name: kibana
kbn-version: 5.3.3
vary: accept-encoding

```

which looks like a response with CORS enabled. Maybe you could elaborate in which way your setup deviates from these steps?

---

<div class="post-metadata">

**Author:** ![PrabakarKaruppasamy](https://avatars.discourse-cdn.com/v4/letter/p/aca169/32.png) [@PrabakarKaruppasamy](https://discuss.elastic.co/u/PrabakarKaruppasamy)\
**Post date:** [July 4, 2017, 1:27pm UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/22 "2017-07-04T13:27:59Z")

</div>

Hello,  
Sorry first of all I am using Kibana 5.4.0 Version.  
I was tried to reproduce the problem in my local environment, but unfortunately I failed.

Set the server.cros:true in config/kibana.yml.

Try to start Kibana using bin/kibana, but facing ValidationError is given below.

```
 name: 'ValidationError',

```

details:  
[ { message: '"cors" must be an object',  
path: 'server.cors',  
type: 'object.base',  
context: [Object] } ],  
\_object:  
{ pkg:  
{ version: '5.4.0',  
buildNum: 15063,  
buildSha: '75afc9fbb024df55fa01acd1a4c2f76d44961746' },  
dev: { basePathProxyTarget: 5603 },  
pid: { exclusive: false },  
cpu: undefined,  
cpuacct: undefined,  
server: { port: 5601, host: '0.0.0.0', cors: true } },  
annotate: [Function] }

If I remove the config setting for the cros and starting the kibana works fine.  
I have checked the dev mode [source](https://github.com/elastic/kibana/blob/5.4/src/ui/index.js#L79) it is printing as _false_ in console.

Expectation is if the Kibana identifies the running mode (Dev or Prod) as the start time that dev mode needs to print as true.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [July 4, 2017, 4:08pm UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/23 "2017-07-04T16:08:43Z")

</div>

And you are running Kibana from an extracted `tar.gz` or installed via `rpm` or `deb`?

---

<div class="post-metadata">

**Author:** ![PrabakarKaruppasamy](https://avatars.discourse-cdn.com/v4/letter/p/aca169/32.png) [@PrabakarKaruppasamy](https://discuss.elastic.co/u/PrabakarKaruppasamy)\
**Post date:** [July 5, 2017, 8:18am UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/24 "2017-07-05T08:18:16Z")

</div>

My local environment (Windows 10) we are running kibana from an extracted zip and our hosted server (Ubuntu) kibana installed via deb.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [July 5, 2017, 9:17am UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/25 "2017-07-05T09:17:09Z")

</div>

I am really not sure what else to try. Let me try to summarize the situation to avoid misunderstandings:

- you are using the official `zip` and `dep` packages of Kibana 5.4.0

- when you add `server.cors: true` to the `kibana.yml` you get a `"cors" must be an object` error when starting Kibana

- when you change nothing except to set `server.cors` to an object like

Is that a correct summary?

---

<div class="post-metadata">

**Author:** ![PrabakarKaruppasamy](https://avatars.discourse-cdn.com/v4/letter/p/aca169/32.png) [@PrabakarKaruppasamy](https://discuss.elastic.co/u/PrabakarKaruppasamy)\
**Post date:** [July 5, 2017, 9:57am UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/26 "2017-07-05T09:57:05Z")

</div>

Hi,

That summary is correct expect three (server.cros ---\> Object ) . As of now we are not trying the third one because we are not running the Kibana in dev mode. Our previous [discussion](https://discuss.elastic.co/t/production-mode-vs-development-mode-in-kibana/91078) .

We are running the kibana in default mode.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [July 5, 2017, 10:20am UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/27 "2017-07-05T10:20:32Z")

</div>

So the third step would qualify as a solution to your problem? There are situations where Kibana considers itself to be running in development mode unless the environment contains `NODE_ENV=production`. If you are not willing to use the object form of the `server.cors` setting, you can try setting this environment explicitly. This will be [fixed](https://github.com/elastic/kibana/pull/12010) in 6.0.

---

<div class="post-metadata">

**Author:** ![PrabakarKaruppasamy](https://avatars.discourse-cdn.com/v4/letter/p/aca169/32.png) [@PrabakarKaruppasamy](https://discuss.elastic.co/u/PrabakarKaruppasamy)\
**Post date:** [July 5, 2017, 10:42am UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/28 "2017-07-05T10:42:00Z")

</div>

> [@weltenwort](#):
>
> NODE\_ENV=production

We are not pretty clear with server.cros setting object. Can you please elaborate the  
origin: ['YOUR', 'ORIGINS', 'HERE']

- What is 'your'

- What is 'ORIGINS'

- What is 'HERE'.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [July 5, 2017, 3:03pm UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/29 "2017-07-05T15:03:00Z")

</div>

Sorry about that. What I meant to express there is that the value of the `origin` setting is an array of string containing the allowed origins. To quote the [hapiJS route documentation](https://hapijs.com/api/14.2.0#route-options):

> a strings array of allowed origin servers ('Access-Control-Allow-Origin'). The array can contain any combination of fully qualified origins along with origin strings containing a wildcard '_' character, or a single '_' origin string. Defaults to any origin ['\*'].

---

<div class="post-metadata">

**Author:** ![PrabakarKaruppasamy](https://avatars.discourse-cdn.com/v4/letter/p/aca169/32.png) [@PrabakarKaruppasamy](https://discuss.elastic.co/u/PrabakarKaruppasamy)\
**Post date:** [July 6, 2017, 7:42am UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/30 "2017-07-06T07:42:50Z")

</div>

We try to set the environment explicitly like `set NODE_ENV=production` in bin/kibana and configured the `server.cros: true` in config file, facing same ValidationError is "cors" must be an object.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [July 6, 2017, 8:57am UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/31 "2017-07-06T08:57:07Z")

</div>

With `bin/kibana` being a shell script the variable needs to be exported as in `export NODE_ENV="production"` in order to be available to child processes.

---

<div class="post-metadata">

**Author:** ![PrabakarKaruppasamy](https://avatars.discourse-cdn.com/v4/letter/p/aca169/32.png) [@PrabakarKaruppasamy](https://discuss.elastic.co/u/PrabakarKaruppasamy)\
**Post date:** [July 10, 2017, 11:29am UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/32 "2017-07-10T11:29:34Z")

</div>

Can we apply same thing for windows batch file?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [July 10, 2017, 5:55pm UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/33 "2017-07-10T17:55:39Z")

</div>

I am not very familiar with windows, but according to the documentation adding `set NODE_ENV=production` to the batch file as you previously suggested should do the trick.

---

<div class="post-metadata">

**Author:** ![PrabakarKaruppasamy](https://avatars.discourse-cdn.com/v4/letter/p/aca169/32.png) [@PrabakarKaruppasamy](https://discuss.elastic.co/u/PrabakarKaruppasamy)\
**Post date:** [July 11, 2017, 8:35am UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/34 "2017-07-11T08:35:56Z")

</div>

We have added `export NODE_ENV="production"` in `bin/kibana` shell script and set cros true in `kibana.yml` like `server.cors: true`. We restarted the kibana service, but still getting cros orgin.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [July 12, 2017, 12:55pm UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/35 "2017-07-12T12:55:54Z")

</div>

Sorry to hear you are still having problems. This is on Ubuntu with Kibana installed using the `.deb`? Are you using systemd or upstart as the init system there?

---

<div class="post-metadata">

**Author:** ![PrabakarKaruppasamy](https://avatars.discourse-cdn.com/v4/letter/p/aca169/32.png) [@PrabakarKaruppasamy](https://discuss.elastic.co/u/PrabakarKaruppasamy)\
**Post date:** [July 13, 2017, 8:00am UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/36 "2017-07-13T08:00:39Z")

</div>

> [@weltenwort](#):
>
> systemd

Yes we installed via `.deb`. We are using SysV init system there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2017, 8:00am UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/37 "2017-08-10T08:00:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

[Previous page](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059.md?page=1)
