# Csp error for custom kibana login page

**URL:** <https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701>\
**Category:** Kibana\
**Created:** [December 6, 2023, 7:01am UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701 "2023-12-06T07:01:40Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Karan\_Lobo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karan_lobo/32/123547_2.png) [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Post date:** [December 6, 2023, 7:01am UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701/1 "2023-12-06T07:01:40Z")

</div>

heeyy i am using a custom plugin for my kibana that changes the login page to give a custom look but i am getting an errror relating to csp

 ![Screenshot 2023-12-06 123018](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c90153aa40e6da0ccd291a6f85c2b1dc9a4e63ce.png)

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [December 6, 2023, 10:17am UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701/2 "2023-12-06T10:17:54Z")

</div>

Hi @Karan_Lobo,

Welcome to the community! Which version of Kibana are you using?

I've not created a plugin myself, but looking at [this similar issue](https://discuss.elastic.co/t/kibana-plugin-development-error-when-creating-plugin-in-kibana-8-6/329264) it might be either a path issue, a conflicting id or a cache issue. Can you try the steps in that thread and see if that solves your issue?

Let us know how it goes!

---

<div class="post-metadata">

**Author:** ![Karan\_Lobo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karan_lobo/32/123547_2.png) [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Post date:** [December 6, 2023, 11:35am UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701/3 "2023-12-06T11:35:45Z")

</div>

Hi thanks for the reply and ii am sorry for not specifying my project.  
I was following this custom kibana theme plugin on kibana 8.10.2  
[GitHub - lizozom/custom-kibana-theme: Customize Kibana's appearance (logos, icons, texts and more)](https://github.com/lizozom/custom-kibana-theme)  
After following all the steps and deploying kibana i was getting the csp error saying that i had to allow inline csp headers . I also read a thread saying to fix this issue i had to go to src/scripts/index.ts file and use the hash code generated to add :  
export const DEFAULT\_CSP\_RULES = Object.freeze([script-src 'unsafe-eval' 'self' 'sha256-P5polb1UreUSOe5V/Pv7tc+yeZuJXiOi/3fqhGsU7BE=']); in it , however i could not find index.ts file in kibana 8.10.2

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [December 6, 2023, 12:07pm UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701/4 "2023-12-06T12:07:09Z")

</div>

Thanks for confirming @Karan_Lobo. That looks to be a community maintained plugin that hasn't been updated since January. I see from the the commits that changes to make it compatible for v8.3, but it could be that perhaps more recent compatible changes haven't been applied.

I'm not sure which thread you're looking at, but I did find [this one](https://github.com/elastic/kibana/issues/30468) that refers to changing `kibana/src/server/csp/index.ts`. In 8.10 I see the equivalent exposed types are included in [`src/core/server/index.ts`](https://github.com/elastic/kibana/blob/8.10/src/core/server/index.ts) so perhaps you could try including the constant there?

If not I would recommend raising an issue against the plugin repository itself.

Hope that helps!

---

<div class="post-metadata">

**Author:** ![Karan\_Lobo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karan_lobo/32/123547_2.png) [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Post date:** [December 7, 2023, 7:40am UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701/5 "2023-12-07T07:40:31Z")

</div>

yeah sorry but it still did not work , is it even possible to change the login page in the free version of kibana 8.10.2 on windows without the custom branding feature??

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [December 7, 2023, 11:54am UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701/6 "2023-12-07T11:54:09Z")

</div>

The custom branding feature is a licensed feature, so not available on the free tier sadly. Th change the theme on free version you would need to use a plugin, either the one you found if compatible or building your own.

Have you tried raising an issue on the repo or reaching out to the contributors to see if they can help?

---

<div class="post-metadata">

**Author:** ![Karan\_Lobo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karan_lobo/32/123547_2.png) [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Post date:** [December 8, 2023, 12:24pm UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701/7 "2023-12-08T12:24:26Z")

</div>

hey sorry for the late response but i tried some things and i added the csp path in my kibana.yaml file  
csp:  
style\_src: [............]  
font\_src: [.............]  
script\_src: ["'unsafe-eval'", "'self'", "'sha256-P5polb1UreUSOe5V/Pv7tc+yeZuJXiOi/3fqhGsU7BE='"]

plugins:  
paths:  
- ....................(no links can be shared)

The thing is the csp error went away and now i am stuck with this error :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/6/56071244354e72000c9ae5992fc8afad3c578fa9.png)

plss help

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [December 11, 2023, 11:15am UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701/8 "2023-12-11T11:15:41Z")

</div>

Hi @Karan_Lobo,

Which browser are you using? Can you check the console in the browser developer tools to get the precise error?

Depending on the precise error and the browsers you need to support you may need to configure your CSP settings as per the [documentation](https://www.elastic.co/guide/en/kibana/current/Security-production-considerations.html#csp-strict-mode) and this [StackOverflow thread](https://stackoverflow.com/questions/74057280/kibana-not-accessible-with-message-please-upgrade-your-browser-from-chrome-10).

---

<div class="post-metadata">

**Author:** ![Karan\_Lobo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karan_lobo/32/123547_2.png) [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Post date:** [December 20, 2023, 6:59am UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701/9 "2023-12-20T06:59:32Z")

</div>

hey @carly.richmond thank you so much for all the help so far, i did find a way to go about the issue unfortunately, the cons far outweigh the pros. I am regretfully canning the project , and thanks again for the support.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [January 5, 2024, 11:42am UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701/10 "2024-01-05T11:42:28Z")

</div>

Sorry to hear @Karan_Lobo. If you found some useful resources for the approach do feel free to share them for others in case they would be useful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2024, 11:42am UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701/11 "2024-02-02T11:42:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
