# Does Kibana need the autorisation of 'unsafe-inline' or 'unsafe-eval' to work properly

**URL:** <https://discuss.elastic.co/t/does-kibana-need-the-autorisation-of-unsafe-inline-or-unsafe-eval-to-work-properly/234390>\
**Category:** Kibana\
**Created:** [May 26, 2020, 5:21pm UTC](https://discuss.elastic.co/t/does-kibana-need-the-autorisation-of-unsafe-inline-or-unsafe-eval-to-work-properly/234390 "2020-05-26T17:21:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Otmane\_Faouzi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/otmane_faouzi/32/54905_2.png) [@Otmane\_Faouzi](https://discuss.elastic.co/u/Otmane_Faouzi)\
**Post date:** [May 26, 2020, 5:21pm UTC](https://discuss.elastic.co/t/does-kibana-need-the-autorisation-of-unsafe-inline-or-unsafe-eval-to-work-properly/234390/1 "2020-05-26T17:21:03Z")

</div>

Hi,

we are using ELK stack under version.

After a scan of our domain on mozilla observatory, the mozilla tool showed us some Recommendation to make the security of our domain better.

So we set int our front (Apache HTTPD 2.4) the Content Security Policy (CSP) to : `script-src 'self'; manifest-src 'self' ; style-src 'self'.`

Kibana is running behind Apache. By doing this modification, the Kibana is broken because kibana is executing some inline javascript:

"Something went wrong ....  
EvalError: Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'self'".

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/f/6f8b47cb12155f7ba05e9ef8a89968272f13e19b.png)  
and also for inline CSS

`Refused to apply inline style because it violates the following Content Security Policy directive: "style-src 'self' . Either the 'unsafe-inline' keyword, a hash ('sha256-9eqTA9rNfDQK1402M6lNw3aW9MsK4p4IfCLxlVEbKkE='), or a nonce ('nonce-...') is required to enable inline execution`

My question is, are we forced to be less restrictive on our Apache by permit execution of inline CSS et Javascript to make Kibana work, and does Kibana really need that?

Is there a way to make the whole work by configuring kibana ?

Best regards,

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [May 26, 2020, 6:30pm UTC](https://discuss.elastic.co/t/does-kibana-need-the-autorisation-of-unsafe-inline-or-unsafe-eval-to-work-properly/234390/2 "2020-05-26T18:30:29Z")

</div>

Hey @Otmane_Faouzi,

Kibana currently requires these `unsafe-*` CSP declarations, but this is something we are trying to improve. Kibana has a number of dependencies which rely on these "unsafe" language features, so we are stuck having to support these for the time being. We have a number of issues where we are tracking CSP enhancements:

- [https://github.com/elastic/kibana/issues/36311](https://github.com/elastic/kibana/issues/36311)
- [https://github.com/elastic/kibana/issues/27047](https://github.com/elastic/kibana/issues/27047)
- [https://github.com/elastic/kibana/issues/56996](https://github.com/elastic/kibana/issues/56996)

---

<div class="post-metadata">

**Author:** ![Otmane\_Faouzi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/otmane_faouzi/32/54905_2.png) [@Otmane\_Faouzi](https://discuss.elastic.co/u/Otmane_Faouzi)\
**Post date:** [May 28, 2020, 2:41pm UTC](https://discuss.elastic.co/t/does-kibana-need-the-autorisation-of-unsafe-inline-or-unsafe-eval-to-work-properly/234390/3 "2020-05-28T14:41:03Z")

</div>

Ok, thanks a lot Larry for you quick answer.

regards,  
Otmane.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2020, 2:41pm UTC](https://discuss.elastic.co/t/does-kibana-need-the-autorisation-of-unsafe-inline-or-unsafe-eval-to-work-properly/234390/4 "2020-06-25T14:41:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
