You have to set the authorization header for all requests sent to Kibana - there are also a lot of Javascript bundles fetched from other places.
To restrict this login to just a single space, create a separate user and role for the reverse proxy and only allow this user access to the desired space (when creating the role, scroll down to the "Kibana" section). This way, Kibana will make sure the user can't access other spaces and you don't have to handle that in the proxy.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.