# How to read a user cookie from Custom Realm plugin

**URL:** <https://discuss.elastic.co/t/how-to-read-a-user-cookie-from-custom-realm-plugin/322224>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [December 30, 2022, 3:35pm UTC](https://discuss.elastic.co/t/how-to-read-a-user-cookie-from-custom-realm-plugin/322224 "2022-12-30T15:35:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wsbr](https://avatars.discourse-cdn.com/v4/letter/w/b9bd4f/32.png) [@wsbr](https://discuss.elastic.co/u/wsbr)\
**Post date:** [December 30, 2022, 3:35pm UTC](https://discuss.elastic.co/t/how-to-read-a-user-cookie-from-custom-realm-plugin/322224/1 "2022-12-30T15:35:34Z")

</div>

Hi folks,

In our solution we are trying to insert a button that redirect to Kibana with the user already logged.

We created a "custom realm" plugin as our unique auth provider to give Kibana access for final users of our solution.

At the moment the users need to insert the username and password in Kibana login page, but as they are already logged in our solution, so we are trying to access the session cookie of my app and make transparent, without login page.

We tried use requestHeadersWhitelist but can't read user cookie.

Anyone know that it is possible?

As a second tentative, we tryed unsuccessful make the button to post an fixed username and the cookie value as password.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 3, 2023, 9:07pm UTC](https://discuss.elastic.co/t/how-to-read-a-user-cookie-from-custom-realm-plugin/322224/2 "2023-01-03T21:07:32Z")

</div>

Hi @wsbr Welcome to the community... Looks like you solved your issue.

It would possibly help other community members if you could show / reference what your solution was.

---

<div class="post-metadata">

**Author:** ![wsbr](https://avatars.discourse-cdn.com/v4/letter/w/b9bd4f/32.png) [@wsbr](https://discuss.elastic.co/u/wsbr)\
**Post date:** [January 3, 2023, 9:35pm UTC](https://discuss.elastic.co/t/how-to-read-a-user-cookie-from-custom-realm-plugin/322224/3 "2023-01-03T21:35:37Z")

</div>

We put a nginx reverse proxy in front of kibana server, using this solution

> **[Rewriting Jwt From Cookies To Authorization Header](https://ashishchaudhary.in/rewriting-jwt-from-cookies-to-authorization-header)**
>
> Some time back I was working on a project (webapp + android app) that uses Postgrest as an API server. The project uses JWT authentication, which is supported out of the box by Postgrest. My project has the following requirements:

Now our custom realm plugin can access our token cookie, that is not and oAuth protocol.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 31, 2023, 9:36pm UTC](https://discuss.elastic.co/t/how-to-read-a-user-cookie-from-custom-realm-plugin/322224/4 "2023-01-31T21:36:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
