# ES cors enabling in ES 2.2

**URL:** <https://discuss.elastic.co/t/es-cors-enabling-in-es-2-2/94320>\
**Category:** Elasticsearch\
**Created:** [July 24, 2017, 11:51am UTC](https://discuss.elastic.co/t/es-cors-enabling-in-es-2-2/94320 "2017-07-24T11:51:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![v.kumar](https://avatars.discourse-cdn.com/v4/letter/v/f475e1/32.png) [@v.kumar](https://discuss.elastic.co/u/v.kumar)\
**Post date:** [July 24, 2017, 11:51am UTC](https://discuss.elastic.co/t/es-cors-enabling-in-es-2-2/94320/1 "2017-07-24T11:51:14Z")

</div>

Elasticsearch by default will not allow cross domain requests.we have to enable CORS (Cross-Origin Resource Sharing) in Elasticsearch configuration file.

I want to try get ES data directly as REST API from javascript front layer. I want to ask, is there any disadvantage of using it ES cors enabling. Or we should make some middle layer to change the header.

Looking forward for your input.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 28, 2017, 6:44am UTC](https://discuss.elastic.co/t/es-cors-enabling-in-es-2-2/94320/2 "2017-07-28T06:44:45Z")

</div>

Enabling CORS will explicitly loosen the security protections that are provided in a browser based environment.

By its very nature, it makes the data you have stored in elasticsearch available in more contexts. A naive configuration of CORS would allow any websites to query your data. A more considered configuration _may_ be secure depending on your environment.

It is impossible for us to perform that risk assessment on your behalf. CORS is disabled by default because that is the only reliable secure setting, but if you are careful and make well-considered choices when enabling CORS, that _can_ be secure as well.

> I want to try get ES data directly as REST API from javascript front layer.

We do not generally recommend that approach. If this is a **private** network, then you _can_ make it work, but we would discourage it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2017, 6:44am UTC](https://discuss.elastic.co/t/es-cors-enabling-in-es-2-2/94320/3 "2017-08-25T06:44:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
