# Header value/HTMLRequest blocked by CORS policy (CORs in Elasticsearch)

**URL:** <https://discuss.elastic.co/t/header-value-htmlrequest-blocked-by-cors-policy-cors-in-elasticsearch/179827>\
**Category:** Elasticsearch\
**Created:** [May 6, 2019, 5:44pm UTC](https://discuss.elastic.co/t/header-value-htmlrequest-blocked-by-cors-policy-cors-in-elasticsearch/179827 "2019-05-06T17:44:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kehinde\_Owens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kehinde_owens/32/42259_2.png) [@Kehinde\_Owens](https://discuss.elastic.co/u/Kehinde_Owens)\
**Post date:** [May 6, 2019, 5:44pm UTC](https://discuss.elastic.co/t/header-value-htmlrequest-blocked-by-cors-policy-cors-in-elasticsearch/179827/1 "2019-05-06T17:44:44Z")

</div>

Morning,

Currently I am facing an issue with CORs not allowing an XMLHTTPRequest from my localhost (when using a header) to my Public Internet URL for Kibana. The error message when making a call to my public URL using a this header:

```auto
const headers = new HttpHeaders({
      'kbn-xsrf' : '6.5.4'
    }); 

```

IS

```auto
Access to XMLHttpRequest at 'https://<URL>.drlteam.net/api/security/v1/login' from origin 'http://localhost:4200' has been blocked by CORS policy: Response to preflight request doesn't pass access control check: No 'Access-Control-Allow-Origin' header is present on the requested resource.

```

But if I make a call without a header the message is:

```auto
HttpErrorResponse {headers: HttpHeaders, status: 400, statusText: "Bad Request", url: "https://<URL>/api/security/v1/login", ok: false, …}
error: {statusCode: 400, error: "Bad Request", message: "Request must contain a kbn-xsrf header."}
headers: HttpHeaders {normalizedNames: Map(0), lazyUpdate: null, lazyInit: ƒ}
message: "Http failure response for https://<URL>/api/security/v1/login: 400 Bad Request"
name: "HttpErrorResponse"
ok: false
status: 400
statusText: "Bad Request"
url: "https://<URL>/api/security/v1/login"
__proto__ : HttpResponseBase

```

The settings in our elasticsearch.yml(s) are:

```auto
http.cors.enabled: true
http.cors.allow-origin: "http://localhost:4200"
http.cors.allow-credentials: true
http.cors.allow-headers: Authorization, kbn-xsrf

```

Not sure where to go from here. Any assistance would be great.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2019, 5:44pm UTC](https://discuss.elastic.co/t/header-value-htmlrequest-blocked-by-cors-policy-cors-in-elasticsearch/179827/2 "2019-06-03T17:44:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
