# Bypass kibana iframe authentication

**URL:** <https://discuss.elastic.co/t/bypass-kibana-iframe-authentication/234324>\
**Category:** Kibana\
**Created:** [May 26, 2020, 12:16pm UTC](https://discuss.elastic.co/t/bypass-kibana-iframe-authentication/234324 "2020-05-26T12:16:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sergio\_Navarrete](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sergio_navarrete/32/69074_2.png) [@Sergio\_Navarrete](https://discuss.elastic.co/u/Sergio_Navarrete)\
**Post date:** [May 26, 2020, 12:16pm UTC](https://discuss.elastic.co/t/bypass-kibana-iframe-authentication/234324/1 "2020-05-26T12:16:11Z")

</div>

Hi,

I have a multitenant web application in which each user will have its own Kibana dashboard embeded in an iframe. I have set up users and roles in elasticsearch with the required priviledges for each user to only access its own dashboard. However the iframe prompt the kibana login page before loading, forcing the client to authenticate. I want to get rid of this.  
I'm aware of the number of posts in this forum about it, but so far there is no satisfactory solution.

I have tried the following:

```auto
POST /api/security/v1/login HTTP/1.1
Host: <kibana_cloud_url>:9243
kbn-version: 7.7.0
Content-Type: application/json
{"username":"user","password":"password"}

```

When invoked from postman I get back an authentication cookie but when invoking it from my code in javascript I get the following error.

```auto
Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at <kibana_cloud_url>:9243/internal/security/login. (Reason: CORS header 'Access-Control-Allow-Origin' missing)

```

According to this post [Unable to perform login on kibana throught browser javascript api call](https://discuss.elastic.co/t/unable-to-perform-login-on-kibana-throught-browser-javascript-api-call/189345/4)  
this is due to CORS not being enabled in Kibana.

Is there any update on that answer?

The other option I have come across is the reverse proxy, however I don't see how can I make that work with Kibana on the cloud and with the dynamic nature of my use case (I dynamically acquire the user credentials to authenticate the dashboard)

Help will be appreciated.

Thanks.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [May 26, 2020, 6:52pm UTC](https://discuss.elastic.co/t/bypass-kibana-iframe-authentication/234324/2 "2020-05-26T18:52:57Z")

</div>

I think the common way to solve this right now is to use proxy in front of Kibana, see [Auto-authenticating to iframe-embedded Kibana dashboard](https://discuss.elastic.co/t/auto-authenticating-to-iframe-embedded-kibana-dashboard/46091/4). Does that work for you?

Also copying @azasypkin for more inputs.

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![Sergio\_Navarrete](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sergio_navarrete/32/69074_2.png) [@Sergio\_Navarrete](https://discuss.elastic.co/u/Sergio_Navarrete)\
**Post date:** [May 26, 2020, 8:07pm UTC](https://discuss.elastic.co/t/bypass-kibana-iframe-authentication/234324/3 "2020-05-26T20:07:06Z")

</div>

Hi @rashmi thanks for your reply.  
I'm afraid the reverse proxy approach does not solve my problem. There are two main issues with that approach.  
1- I'm using kibana in elastic cloud, how can I create a reverse proxy for it ?  
2- My credentials are dynamically generated, I don't know them in advance so I can't put them in a static config.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2020, 8:07pm UTC](https://discuss.elastic.co/t/bypass-kibana-iframe-authentication/234324/4 "2020-06-23T20:07:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
