# Error 401-Unauthorized when using js/elasticsearch to query my (Cloud) cluster

**URL:** <https://discuss.elastic.co/t/error-401-unauthorized-when-using-js-elasticsearch-to-query-my-cloud-cluster/76811>\
**Category:** Elasticsearch\
**Created:** [February 28, 2017, 3:39pm UTC](https://discuss.elastic.co/t/error-401-unauthorized-when-using-js-elasticsearch-to-query-my-cloud-cluster/76811 "2017-02-28T15:39:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cylindric](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cylindric/32/5660_2.png) [@Cylindric](https://discuss.elastic.co/u/Cylindric)\
**Post date:** [February 28, 2017, 3:39pm UTC](https://discuss.elastic.co/t/error-401-unauthorized-when-using-js-elasticsearch-to-query-my-cloud-cluster/76811/1 "2017-02-28T15:39:47Z")

</div>

Hi folks. I've been having some trouble over in the Cloud Category getting my custom dashboard to talk to my ES cluster, and despite a bunch of help with `cors` settings, it still doesn't seem to be working. I may be doing something daft, but can't find out what.

I have a simple static HTML page that calls this bit of js:

```
define(['js/d3.v3', 'js/elasticsearch'], function (d3, elasticsearch) {
    "use strict";
    var client = new elasticsearch.Client({
		host: 'https://myusername:mypassword@mycluster.eu-west-1.aws.found.io:9243', log: 'trace'});
	
	client.ping({
		requestTimeout: 10000
	}, function(error){
		if (error) {
			console.trace('elasticsearch cluster is down!');
			console.trace(error);
		} else {
			console.log('All is well');
		}
	});
});

```

And all I get in my Chrome dev tools is a `401 Unauthorized` response.

With the help of @bevacqua I have my elasticsearch.yml settings now as follows:

```
http.cors.allow-credentials: true
http.cors.enabled: true
http.cors.allow-origin: "http://nagios.communigator.co.uk"
http.cors.allow-headers: "X-Requested-With, Content-Type, Content-Length, Authorization"

```

related questions for reference:

[Change to CORS setting seems to have broken Kopf](https://discuss.elastic.co/t/change-to-cors-setting-seems-to-have-broken-kopf/76597)  
[Using js/elasticsearch with a cluster instance](https://discuss.elastic.co/t/using-js-elasticsearch-with-a-cluster-instance/75774)

---

<div class="post-metadata">

**Author:** ![Cylindric](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cylindric/32/5660_2.png) [@Cylindric](https://discuss.elastic.co/u/Cylindric)\
**Post date:** [March 21, 2017, 3:11pm UTC](https://discuss.elastic.co/t/error-401-unauthorized-when-using-js-elasticsearch-to-query-my-cloud-cluster/76811/2 "2017-03-21T15:11:23Z")

</div>

Okay so I finally got a chance to revisit this now. According to my User Settings in the cloud control panel (cluster 1e7502), my CORS settings are:

```
http.cors.enabled: false
http.cors.allow-origin: "http://nagios.communigator.co.uk"
http.cors.allow-credentials: true

```

I believe it was a GUI error that was preventing me from adding the final setting, but I have been assured that is there too. I have no way to confirm that my self.

```
http.cors.allow-headers: "X-Requested-With, Content-Type, Content-Length, Authorization"

```

I have just checked the trivial example above again, and I am definitely getting `401 Unauthorized` errors. I just logged into Kibana using the username and passsword I have in my javascript and that worked fine.

Here are the headers from the failed request:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/2/8272e7c07e85f250a3eafce57a0349560917b2fd.png)

---

<div class="post-metadata">

**Author:** ![Cylindric](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cylindric/32/5660_2.png) [@Cylindric](https://discuss.elastic.co/u/Cylindric)\
**Post date:** [March 29, 2017, 9:07am UTC](https://discuss.elastic.co/t/error-401-unauthorized-when-using-js-elasticsearch-to-query-my-cloud-cluster/76811/3 "2017-03-29T09:07:57Z")

</div>

I don't suppose anyone has any ideas on this one? I didn't get much response in the #cloud category either. Does _nobody_ access their ES data like this? Should I be using some other method?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2017, 9:08am UTC](https://discuss.elastic.co/t/error-401-unauthorized-when-using-js-elasticsearch-to-query-my-cloud-cluster/76811/4 "2017-04-26T09:08:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
