# Get request with query yields result in Firefox, but nowhere else

**URL:** <https://discuss.elastic.co/t/get-request-with-query-yields-result-in-firefox-but-nowhere-else/334422>\
**Category:** Elasticsearch\
**Created:** [May 26, 2023, 10:44am UTC](https://discuss.elastic.co/t/get-request-with-query-yields-result-in-firefox-but-nowhere-else/334422 "2023-05-26T10:44:58Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fiothiel](https://avatars.discourse-cdn.com/v4/letter/f/e19b73/32.png) [@Fiothiel](https://discuss.elastic.co/u/Fiothiel)\
**Post date:** [May 26, 2023, 10:44am UTC](https://discuss.elastic.co/t/get-request-with-query-yields-result-in-firefox-but-nowhere-else/334422/1 "2023-05-26T10:44:59Z")

</div>

Hello,  
I have a rather strange issue I would love to get some help with. I am running Elastic Search 7.7 locally and I'm trying to implement a very basic search call to it.  
When I call it without any query parameters it works and I get hits:  
[http://localhost:9200/i5tripdocument.invariant/\_search](http://localhost:9200/i5tripdocument.invariant/_search)

This is both in my browser and Postman. Now, when I DO add a query parameter for something that should yield hits, I get hits when I run it in Firefox. If I run it in another browser (Chrome, Edge) or in Postman, I get zero hits.  
[http://localhost:9200/i5tripdocument.invariant/\_search?q=query](http://localhost:9200/i5tripdocument.invariant/_search?q=query)

I have copied the exact request from Firefox and imported into Postman, but with the same result.

I tried adding "http.cors.enabled: false" to my elasticsearch.yml (tip from a colleague), but that made no difference.

Has anyone encountered this?

Thanks in advance,  
Kristina

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [May 28, 2023, 5:29pm UTC](https://discuss.elastic.co/t/get-request-with-query-yields-result-in-firefox-but-nowhere-else/334422/2 "2023-05-28T17:29:02Z")

</div>

Hello @Fiothiel,

Have you tried updating `http.cors.allow-origin` to allow requests from any origin (\*)?

Updating this to something like:

```auto
 http.cors.allow-origin: "*"

```

To rule out cache-related issues, you can also try clearing your browser cache.

---

<div class="post-metadata">

**Author:** ![Fiothiel](https://avatars.discourse-cdn.com/v4/letter/f/e19b73/32.png) [@Fiothiel](https://discuss.elastic.co/u/Fiothiel)\
**Post date:** [May 29, 2023, 7:05am UTC](https://discuss.elastic.co/t/get-request-with-query-yields-result-in-firefox-but-nowhere-else/334422/3 "2023-05-29T07:05:24Z")

</div>

Hi!  
I tried what you suggested but it didn't change anything 😕 And I have tried in incognito browser windows as well to rule out cache issues.

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [May 29, 2023, 12:46pm UTC](https://discuss.elastic.co/t/get-request-with-query-yields-result-in-firefox-but-nowhere-else/334422/4 "2023-05-29T12:46:44Z")

</div>

Hello @Fiothiel,

Update: As per this [PR](https://github.com/elastic/kibana/pull/59096), CORS customization were available prior to 7.11, but only when running in dev mode.

What is your use case for requiring API calls from your web application?

---

<div class="post-metadata">

**Author:** ![Fiothiel](https://avatars.discourse-cdn.com/v4/letter/f/e19b73/32.png) [@Fiothiel](https://discuss.elastic.co/u/Fiothiel)\
**Post date:** [May 30, 2023, 7:56am UTC](https://discuss.elastic.co/t/get-request-with-query-yields-result-in-firefox-but-nowhere-else/334422/5 "2023-05-30T07:56:02Z")

</div>

We use Elastic Search with Litium 7 ([Litium CMS](https://www.litium.com/product/cms)). Litium has built in functionality for Elastic Search and we use that, but for over a year we've had issues with some of our documents not being automatically indexed. When the index is rebuilt manually, the document appears. We haven't found anything in our code that goes kaboom, and Litium can't see anything wrong either. So I want to implement this so that when a document doesn't seem to get indexed, I can go _straight_ to Elastic Search and see if it is in fact there, even if we don't get any hits when going through Litium.

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [May 30, 2023, 3:04pm UTC](https://discuss.elastic.co/t/get-request-with-query-yields-result-in-firefox-but-nowhere-else/334422/6 "2023-05-30T15:04:43Z")

</div>

Thank you for sharing this additional context.

Well, I don't know this Litium CMS functionality. Can you share with me your `elasticsearch.yml`?

You can try something like this:

```auto
http.cors.enabled: true
http.cors.allow-origin: "*"
http.cors.allow-methods: OPTIONS, HEAD, GET, POST, PUT, DELETE
http.cors.allow-headers: X-Requested-With,X-Auth-Token,Content-Type,Content-Length
http.cors.allow-credentials: false

```

[Here](https://github.com/elastic/kibana/issues/16714) is the context of this suggestion - updating `http.cors.allow-credentials` to `false` and `http.cors.allow-origin` to `"*"`, but as [mentioned here,](https://github.com/elastic/kibana/pull/59096) this is not supported in production, for production you can use a specific origin value, like `http.cors.allow-origin: "https://<my-website-domain.example>"`.

Since what you need is just to visualize this data to confirm if it is there, you can also use [Kibana Dev Tool](https://www.elastic.co/guide/en/kibana/7.7/console-kibana.html), [Discover](https://www.elastic.co/guide/en/kibana/7.7/discover.html), or even [curl](https://www.elastic.co/guide/en/cloud/current/ec-working-with-elasticsearch.html).

Hope this helps!

---

<div class="post-metadata">

**Author:** ![Fiothiel](https://avatars.discourse-cdn.com/v4/letter/f/e19b73/32.png) [@Fiothiel](https://discuss.elastic.co/u/Fiothiel)\
**Post date:** [June 15, 2023, 9:17am UTC](https://discuss.elastic.co/t/get-request-with-query-yields-result-in-firefox-but-nowhere-else/334422/7 "2023-06-15T09:17:41Z")

</div>

Hi!  
I'm sorry for the long reply. Thank you for your suggestions. Unfortunately I get the same result using curl. I get hits when I don't include any parameters, and when I do include a query parameter (that definitely should yield a hit), it doesn't. Unless there is something I have to set up when I do the call?  
If I put it like this in my browser (well, my Firefox browser..) it works:  
[http://localhost:9200/i5tripdocument.invariant/\_search?q=SomethingThatDefinitelyShouldYieldAHit](http://localhost:9200/i5tripdocument.invariant/_search?q=SomethingThatDefinitelyShouldYieldAHit)

Is there any kind of "these are the things I want you to look through" things that should be added to the api call (or curl or whichever) that I've missed?

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [June 15, 2023, 2:33pm UTC](https://discuss.elastic.co/t/get-request-with-query-yields-result-in-firefox-but-nowhere-else/334422/8 "2023-06-15T14:33:32Z")

</div>

Hm, it should work from your command line, so the problem is not in the CORS config.

Can I see the query you used in your curl request? What was the response?

Let's test something to match all documents. Could you please add a body with a [match all query](https://www.elastic.co/guide/en/elasticsearch/reference/7.7/query-dsl-match-all-query.html) to your request in Postman?

```auto
POST localhost:9200/i5tripdocument.invariant/_search
{
    "query": {
        "match_all": {}
    }
}

```

Btw, Do you have access to Kibana using this tool?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2023, 2:34pm UTC](https://discuss.elastic.co/t/get-request-with-query-yields-result-in-firefox-but-nowhere-else/334422/9 "2023-07-13T14:34:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
