# How to get response header with cookie from POST request to Kibana REST API /internal/security/login

**URL:** <https://discuss.elastic.co/t/how-to-get-response-header-with-cookie-from-post-request-to-kibana-rest-api-internal-security-login/262530>\
**Category:** Kibana\
**Created:** [January 28, 2021, 4:21pm UTC](https://discuss.elastic.co/t/how-to-get-response-header-with-cookie-from-post-request-to-kibana-rest-api-internal-security-login/262530 "2021-01-28T16:21:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gaetano](https://avatars.discourse-cdn.com/v4/letter/g/b9e5f3/32.png) [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Post date:** [January 28, 2021, 4:21pm UTC](https://discuss.elastic.co/t/how-to-get-response-header-with-cookie-from-post-request-to-kibana-rest-api-internal-security-login/262530/1 "2021-01-28T16:21:57Z")

</div>

My goal is to skip login page in Kibana.  
With an HTTP request, I would to login in Kibana using the REST API **/internal/security/login**.  
The request is come from my Angular application and to bypass CORS and multi-origin, I edited the `http_tools.js` adding this line  
`cors: { additionalHeaders: ['kbn-version','kbn-xsrf','cookie'], origin: ['*'], credentials: true },`  
instead of  
`cors: config.cors,`

This is the code of the Angular request:

```auto
        fetch(environment.URL_login, {
          method: 'POST', body: body,
          credentials: 'include', headers: {'Content-Type': 'application/json',
          'kbn-version': '7.6.2'},
        }).then(res => {
          console.log(res);
          window.open(environment.URL, "_blank");

```

The post call returns me status 204 and a Response containing empty headers.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/a/9a5ccecd35bd0c4533ce01e9c94501b659b5d79b.png)  
If I click on the Network tab of the Inspector Chrome, I see the cookie created in **Cookies** section.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/7/c757b66fb229ea9f8a1ba9fd0fe8523e8484d4f7.png)  
How can I get the cookie, that is dynamically created by kibana, within the response that I obtain from the http post?

---

<div class="post-metadata">

**Author:** ![bard0x](https://avatars.discourse-cdn.com/v4/letter/b/5fc32e/32.png) [@bard0x](https://discuss.elastic.co/u/bard0x)\
**Post date:** [January 29, 2021, 7:12am UTC](https://discuss.elastic.co/t/how-to-get-response-header-with-cookie-from-post-request-to-kibana-rest-api-internal-security-login/262530/2 "2021-01-29T07:12:27Z")

</div>

I have the similar problem...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2021, 7:13am UTC](https://discuss.elastic.co/t/how-to-get-response-header-with-cookie-from-post-request-to-kibana-rest-api-internal-security-login/262530/3 "2021-02-26T07:13:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
