# \[Filebeat\]\[xpack\]\[httpjson\] - OAuth2 use without client secret and with url params is not possible

**URL:** <https://discuss.elastic.co/t/filebeat-xpack-httpjson-oauth2-use-without-client-secret-and-with-url-params-is-not-possible/314691>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 19, 2022, 12:04pm UTC](https://discuss.elastic.co/t/filebeat-xpack-httpjson-oauth2-use-without-client-secret-and-with-url-params-is-not-possible/314691 "2022-09-19T12:04:31Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![p-leh](https://avatars.discourse-cdn.com/v4/letter/p/7993a0/32.png) [@p-leh](https://discuss.elastic.co/u/p-leh)\
**Post date:** [September 19, 2022, 12:04pm UTC](https://discuss.elastic.co/t/filebeat-xpack-httpjson-oauth2-use-without-client-secret-and-with-url-params-is-not-possible/314691/1 "2022-09-19T12:04:31Z")

</div>

The xpack input module httpjson for filebeat can handle the OAuth2 process.  
We want to use httpjson against a cloud foundry setup which is not possible. The problem comes up because on two hard coded contraints:

- the "client\_id" and "client\_secret" is sent in the POST body as application/x-www-form-urlencoded parameters
- the cliend\_id and client\_secret has been set.

In our example we needed to adjust the folliwing file to get the input module running as expected because the clientsecret was null and the client credentials within the body not supported:

x-pack-\>filebeat-\>input-\>httpjson-\>config\_auth.go  
LINE 25:

```auto
// authStyleInParams sends the "client_id" and "client_secret" in the POST body as application/x-www-form-urlencoded parameters.
//const authStyleInParams = 1
// Change to Auto Detection
const authStyleAutoDetect = 0

```

LINE 216

```auto
// exclude the ClientSecret from Param Validator:
	case oAuth2ProviderDefault:
		if o.TokenURL == "" || o.ClientID == "" { //|| o.ClientSecret == ""
			return errors.New("both token_url and client.id credentials must be provided")
		}
		if (o.User != "" && o.Password == "") || (o.User == "" && o.Password != "") {
			return errors.New("both user and password credentials must be provided")
		}
	default:

```

I'm new to distribute to open source software and I want to ask how does the process goes further?  
I would like to create a Bug / PullRequest for this issue but I read that this forum is the starting point. Is this correct?

KInd regards,  
Patrick

---

<div class="post-metadata">

**Author:** ![Tetiana\_Kravchenko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tetiana_kravchenko/32/102683_2.png) [@Tetiana\_Kravchenko](https://discuss.elastic.co/u/Tetiana_Kravchenko)\
**Post date:** [September 22, 2022, 2:46pm UTC](https://discuss.elastic.co/t/filebeat-xpack-httpjson-oauth2-use-without-client-secret-and-with-url-params-is-not-possible/314691/2 "2022-09-22T14:46:04Z")

</div>

@TiagoQueiroz maybe you or someone from the data plane teams could have a look here, as it related to the httpjson input. should the PR for this use case be opened?

---

<div class="post-metadata">

**Author:** ![TiagoQueiroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tiagoqueiroz/32/107061_2.png) [@TiagoQueiroz](https://discuss.elastic.co/u/TiagoQueiroz)\
**Post date:** [September 29, 2022, 1:24pm UTC](https://discuss.elastic.co/t/filebeat-xpack-httpjson-oauth2-use-without-client-secret-and-with-url-params-is-not-possible/314691/3 "2022-09-29T13:24:56Z")

</div>

Hi @p-leh,

this seems to be a legit feature improvement. If I understood correctly, you need to use OAuth2 but passing the credentials in a different way, is that it?

Could you provide more details about how the request needs to be setup?

Without fully understanding your need, it seems what you're asking for is a different way to setup/pass the OAuth2 credentials in the request. Is that it?

---

<div class="post-metadata">

**Author:** ![p-leh](https://avatars.discourse-cdn.com/v4/letter/p/7993a0/32.png) [@p-leh](https://discuss.elastic.co/u/p-leh)\
**Post date:** [October 10, 2022, 8:07am UTC](https://discuss.elastic.co/t/filebeat-xpack-httpjson-oauth2-use-without-client-secret-and-with-url-params-is-not-possible/314691/4 "2022-10-10T08:07:57Z")

</div>

Hi @TiagoQueiroz,

yes your guess is right:  
1.) I want the option, that the credentials going to be passed as Header params as well or even better to use the automatic function from the oauth2 package. ([oauth2 package - golang.org/x/oauth2 - Go Packages](https://pkg.go.dev/golang.org/x/oauth2#AuthStyle))  
2.) The passing of the required client credentials is to strict, because the param validator checks the client secret as well. But the client secret can be empty too and even still valid for oauth2 access process.

Regards,  
Patrick

---

<div class="post-metadata">

**Author:** ![TiagoQueiroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tiagoqueiroz/32/107061_2.png) [@TiagoQueiroz](https://discuss.elastic.co/u/TiagoQueiroz)\
**Post date:** [October 10, 2022, 2:31pm UTC](https://discuss.elastic.co/t/filebeat-xpack-httpjson-oauth2-use-without-client-secret-and-with-url-params-is-not-possible/314691/5 "2022-10-10T14:31:43Z")

</div>

Hi @p-leh,

that looks like a legit enhancement request, could you [open an issue on GitHub describing it](https://github.com/elastic/beats/issues/new?assignees=&labels=&template=feature-request.md)? It would add a new way of authenticating, if my understanding is correct.

Feel free to also send a PR (create the issue first, then assign it to yourself so we know you're working on it).

---

<div class="post-metadata">

**Author:** ![p-leh](https://avatars.discourse-cdn.com/v4/letter/p/7993a0/32.png) [@p-leh](https://discuss.elastic.co/u/p-leh)\
**Post date:** [October 12, 2022, 6:16am UTC](https://discuss.elastic.co/t/filebeat-xpack-httpjson-oauth2-use-without-client-secret-and-with-url-params-is-not-possible/314691/6 "2022-10-12T06:16:55Z")

</div>

Hi @TiagoQueiroz  
thx for your support!  
I've created the issue but I cannot assign myself to it and the bot labeled it with need\_teams.  
Did I do something wrong?

Regards,  
Patrick

---

<div class="post-metadata">

**Author:** ![TiagoQueiroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tiagoqueiroz/32/107061_2.png) [@TiagoQueiroz](https://discuss.elastic.co/u/TiagoQueiroz)\
**Post date:** [October 12, 2022, 8:49am UTC](https://discuss.elastic.co/t/filebeat-xpack-httpjson-oauth2-use-without-client-secret-and-with-url-params-is-not-possible/314691/7 "2022-10-12T08:49:57Z")

</div>

Hi @p-leh, post the link here and I'll take a look at it.

---

<div class="post-metadata">

**Author:** ![p-leh](https://avatars.discourse-cdn.com/v4/letter/p/7993a0/32.png) [@p-leh](https://discuss.elastic.co/u/p-leh)\
**Post date:** [October 12, 2022, 9:16am UTC](https://discuss.elastic.co/t/filebeat-xpack-httpjson-oauth2-use-without-client-secret-and-with-url-params-is-not-possible/314691/8 "2022-10-12T09:16:17Z")

</div>

Hi @TiagoQueiroz ,

thx: [[Filebeat][xpack][httpjson] - OAuth2 use without client secret and with url params is not possible · Issue #33327 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/33327)

---

<div class="post-metadata">

**Author:** ![TiagoQueiroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tiagoqueiroz/32/107061_2.png) [@TiagoQueiroz](https://discuss.elastic.co/u/TiagoQueiroz)\
**Post date:** [October 12, 2022, 9:33am UTC](https://discuss.elastic.co/t/filebeat-xpack-httpjson-oauth2-use-without-client-secret-and-with-url-params-is-not-possible/314691/9 "2022-10-12T09:33:32Z")

</div>

Thanks!

I managed to assign it to you. The `needs-team` label is normal, ideally every issue/PR is assigned to one of our teams, hence the automation adds this `needs-team` label until we properly label it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2022, 11:33am UTC](https://discuss.elastic.co/t/filebeat-xpack-httpjson-oauth2-use-without-client-secret-and-with-url-params-is-not-possible/314691/10 "2022-11-09T11:33:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
