# CSP errors when using an Kibana iframe

**URL:** <https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096>\
**Category:** Kibana\
**Created:** [August 24, 2020, 10:28am UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096 "2020-08-24T10:28:46Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sharry\_Stowell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharry_stowell/32/74397_2.png) [@Sharry\_Stowell](https://discuss.elastic.co/u/Sharry_Stowell)\
**Post date:** [August 24, 2020, 10:28am UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/1 "2020-08-24T10:28:46Z")

</div>

Running into CSP errors when using dashboard \> share \> embed \> iframe. Copied the iframe to a local html file & pasted it there.

```auto
<html>
<body>
<iframe src="https://kibana.myurl:5601/app/dashboards#/view/fc6ea5f0-e3bf-11ea-84c0-073e1429eecc?embed=true&_g=(filters%3A!()%2CrefreshInterval%3A(pause%3A!t%2Cvalue%3A0)%2Ctime%3A(from%3Anow-15M%2Cto%3Anow))&show-top-menu=true&show-query-input=true&show-time-filter=true" frameBorder="0" height="750" width="1200"></iframe>
</body>
</html>

```

Resulting in:  
`Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'unsafe-eval' 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-P5polb1UreUSOe5V/Pv7tc+yeZuJXiOi/3fqhGsU7BE='), or a nonce ('nonce-...') is required to enable inline execution.`

When I try to login using working login it just loops back to show the same login screen.

**Versions:**  
ElasticSearch 7.9.0  
Kibana: 7.9.0

 ![DeepinScreenshot_select-area_20200824100357](https://us1.discourse-cdn.com/elastic/original/3X/a/b/abd0b53b0fcddd57fd51287feacd1ebd6e64c31e.png)

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [August 24, 2020, 12:48pm UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/2 "2020-08-24T12:48:30Z")

</div>

Hi,  
As the message below it says - `A single error about an inline script not firing due to content security policy is expected`. This is unfortunate, and we have an [issue](https://github.com/elastic/kibana/issues/30468) open to fix this behavior. So I don't think this is related to your issue.  
Users you are sharing this with must have Kibana access to view an embedded dashboard.

Have you managed to share any other dashboard? Do they all result in the same problem?

---

<div class="post-metadata">

**Author:** ![Sharry\_Stowell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharry_stowell/32/74397_2.png) [@Sharry\_Stowell](https://discuss.elastic.co/u/Sharry_Stowell)\
**Post date:** [August 24, 2020, 1:46pm UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/3 "2020-08-24T13:46:22Z")

</div>

Hi, thanks for getting back to me.

I only have 1 dashboard at the moment, just using the elastic (root) user to login to Kibana but keeps redirecting to itself

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [August 24, 2020, 2:54pm UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/4 "2020-08-24T14:54:34Z")

</div>

I managed to reproduce this, looking into it now

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [August 24, 2020, 2:55pm UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/5 "2020-08-24T14:55:54Z")

</div>

Do you have mutiple spaces defined?

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [August 24, 2020, 3:09pm UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/6 "2020-08-24T15:09:37Z")

</div>

And which browser are you using to access the shared dashboard?

---

<div class="post-metadata">

**Author:** ![User4](https://avatars.discourse-cdn.com/v4/letter/u/7cd45c/32.png) [@User4](https://discuss.elastic.co/u/User4)\
**Post date:** [August 24, 2020, 3:19pm UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/7 "2020-08-24T15:19:02Z")

</div>

Hello! I faced the same problem today. Kibana is loaded into the iframe, and constantly asks for a login-password, I enter the correct login-password, but does not let it into the interface and again requires input. The errors in the console are the same. I registered in kibana.yml - csp.rules: "frame-src http: // localhost: 8080" - it does not help. Tell me how to completely disable CSP for Kibana? I don't need CSP.  
At the same time - if you open the link (which opens in an iframe) in a separate tab - everything works correctly

---

<div class="post-metadata">

**Author:** ![Sharry\_Stowell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharry_stowell/32/74397_2.png) [@Sharry\_Stowell](https://discuss.elastic.co/u/Sharry_Stowell)\
**Post date:** [August 24, 2020, 3:34pm UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/8 "2020-08-24T15:34:20Z")

</div>

Hi, Chrome: Version 83.0.4103.61 (Official Build) (64-bit)

No spaces are setup, just the default one.

---

<div class="post-metadata">

**Author:** ![Sharry\_Stowell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharry_stowell/32/74397_2.png) [@Sharry\_Stowell](https://discuss.elastic.co/u/Sharry_Stowell)\
**Post date:** [August 24, 2020, 3:36pm UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/9 "2020-08-24T15:36:13Z")

</div>

My Kibana is running in https, have to tried running in https rather than http on localhost?

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [August 25, 2020, 8:16am UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/10 "2020-08-25T08:16:23Z")

</div>

Thanks for reporting this @Sharry_Stowell and @User4. We've been getting several reports of this issue. Before digging into this further, could I just ask you to confirm your Kibana version and browser version you're using?

---

<div class="post-metadata">

**Author:** ![User4](https://avatars.discourse-cdn.com/v4/letter/u/7cd45c/32.png) [@User4](https://discuss.elastic.co/u/User4)\
**Post date:** [August 25, 2020, 9:33am UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/11 "2020-08-25T09:33:47Z")

</div>

Thanks for noticing this issue! The version of the Google Chrome browser is 83.0.4103.97. Kibana version v 7.8.0. In Firefox 76.0 (64-bit) has no problem, Kibana loads correctly

---

<div class="post-metadata">

**Author:** ![Sharry\_Stowell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharry_stowell/32/74397_2.png) [@Sharry\_Stowell](https://discuss.elastic.co/u/Sharry_Stowell)\
**Post date:** [August 26, 2020, 7:54am UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/12 "2020-08-26T07:54:53Z")

</div>

> [@Sharry\_Stowell](#):
>
> Chrome: Version 83.0.4103.61 (Official Build) (64-bit)

Sure:

Linux Chrome: Version 83.0.4103.61 (Official Build) (64-bit)  
Elasticsearch 7.9.0  
Kibana: 7.9.0

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [August 26, 2020, 8:53am UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/13 "2020-08-26T08:53:48Z")

</div>

We've had a similar issue after the latest Chrome upgrade. The solution there was to set `sameSiteCookies: None` in `kibana.yml` and use https (otherwise Chrome won't respect the setting). This will work for Kibana versions 7.8.1 and above

But this other error was only affecting the latest Chrome - 84.0.4147.135 - which neither of you are using, so I'm not sure if this is the same issue or if the solution would help you.

Could you try this and let me know if the issue still persists?

---

<div class="post-metadata">

**Author:** ![Sharry\_Stowell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharry_stowell/32/74397_2.png) [@Sharry\_Stowell](https://discuss.elastic.co/u/Sharry_Stowell)\
**Post date:** [August 26, 2020, 9:10am UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/14 "2020-08-26T09:10:10Z")

</div>

Thank you, I'll have a go 🙂

---

<div class="post-metadata">

**Author:** ![Sharry\_Stowell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharry_stowell/32/74397_2.png) [@Sharry\_Stowell](https://discuss.elastic.co/u/Sharry_Stowell)\
**Post date:** [August 26, 2020, 10:19am UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/15 "2020-08-26T10:19:42Z")

</div>

Do you mean:  
_xpack.security.sameSiteCookies: None_

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [August 27, 2020, 6:51am UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/16 "2020-08-27T06:51:46Z")

</div>

Yes, sorry for not making this more clear

---

<div class="post-metadata">

**Author:** ![Soundarya\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/soundarya_r/32/46287_2.png) [@Soundarya\_R](https://discuss.elastic.co/u/Soundarya_R)\
**Post date:** [August 28, 2020, 4:22am UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/17 "2020-08-28T04:22:40Z")

</div>

My version of the Google Chrome browser is 85.0.4183.83 (64-bit). Kibana version v 7.7.1.  
I've included kibana dashboard into my external web application which I'm running locally and kibana is in cloud. A week before it was working perfectly. But from start of this week, I'm getting this error _ **"A single error about an inline script not firing due to content security policy is expected"** _ . Kindly help me out from this issue. Thanks in advance!!

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [August 28, 2020, 5:48am UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/18 "2020-08-28T05:48:31Z")

</div>

Hi, as the message says - a single error is expected. That error message has been there for a while. If Kibana is loading fine, you shouldn't worry about that particular error message.

---

<div class="post-metadata">

**Author:** ![Soundarya\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/soundarya_r/32/46287_2.png) [@Soundarya\_R](https://discuss.elastic.co/u/Soundarya_R)\
**Post date:** [September 1, 2020, 4:00am UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/19 "2020-09-01T04:00:18Z")

</div>

Still continuing with same problem as I mentioned above. Kibana cloud is working absolutely fine. But I couldn't access in my external application. Getting this below error. I couldn't get proper source of the problem and solution. Kindly help me out.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/6/c6b8743191a357fcfac552722a37f2d76cd7e5a2.png)

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [September 7, 2020, 2:54pm UTC](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096/20 "2020-09-07T14:54:20Z")

</div>

Have you tried the solution with `sameSiteCookies: None` and it still didn't work?

[Next page](https://discuss.elastic.co/t/csp-errors-when-using-an-kibana-iframe/246096.md?page=2)
