# How to set SameSite='None' in Kibana 7.6.2

**URL:** <https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633>\
**Category:** Kibana\
**Created:** [January 29, 2021, 11:22am UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633 "2021-01-29T11:22:49Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![gaetano](https://avatars.discourse-cdn.com/v4/letter/g/b9e5f3/32.png) [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Post date:** [January 29, 2021, 11:22am UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/1 "2021-01-29T11:22:49Z")

</div>

I'm using kibana 7.6.2 version and I tried to execute a cross-site domain access to Kibana bypassing login page.  
After I launched http post call to Kibana login endpoint, attaching username and password,  
I obtain a warning in Cookie section.

If I moved the mouse pointer to (i) of **SameSite** column, I get the following message back:  
**This Set-Cookie didn't specify a "SameSite" attributed and was defaulted to "SameSite=Lax" and was blocked because it came from a cross-site response which was not the response to a top-level navigation. The Set-Cookie had to have been set with "SameSite=None" to enable cross-site usage.**

![cookie](https://us1.discourse-cdn.com/elastic/original/3X/9/7/976bf6dcef924962f34dd5dafd4d9b3687900043.png)

it seems that in version 7.6.2 the `SameSite` setting to `None` is not enabled, but in the `http_tools.js` there is a boolean variable `isSameSite` which by default is set to `false`.  
How can I fix this bug?

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [January 29, 2021, 3:31pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/2 "2021-01-29T15:31:16Z")

</div>

Hello @gaetano

Generally speaking, its preferred to keep this in place as its more secure.

Why do you wish to make the cross site request?

---

<div class="post-metadata">

**Author:** ![gaetano](https://avatars.discourse-cdn.com/v4/letter/g/b9e5f3/32.png) [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Post date:** [January 30, 2021, 5:48pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/3 "2021-01-30T17:48:51Z")

</div>

Hi  
I have a programming environment consisting of some virtual machines on which some web applications have been deployed. Solving this problem will allow me to connect between endpoints on different virtual machines.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [January 30, 2021, 7:44pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/4 "2021-01-30T19:44:17Z")

</div>

I see - and how are you making the request to kibana? What does the request do and what are your aims?

---

<div class="post-metadata">

**Author:** ![gaetano](https://avatars.discourse-cdn.com/v4/letter/g/b9e5f3/32.png) [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Post date:** [January 30, 2021, 7:48pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/5 "2021-01-30T19:48:30Z")

</div>

my goal is to access kibana bypassing the login page by attaching username and password in the http post request

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [January 30, 2021, 7:53pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/6 "2021-01-30T19:53:03Z")

</div>

What does the request do? Are you using this to skip the login page and use kibana as normal or are you attempting to automate something?

* * *

Based on what you've said so far the best path would be to place a proxy in front of kibana so it can be served from the same ip or domain as the script you're trying to run but if you let me know what you're trying to do we might find something simpler.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [January 30, 2021, 8:04pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/7 "2021-01-30T20:04:04Z")

</div>

You could also disable CORS enforcement in your browser although I wouldn't recommend it as a long term solution - [Allow CORS: Access-Control-Allow-Origin - Chrome Web Store](https://chrome.google.com/webstore/detail/allow-cors-access-control/lhobafahddgcelffkeicbaginigeejlf)

---

<div class="post-metadata">

**Author:** ![gaetano](https://avatars.discourse-cdn.com/v4/letter/g/b9e5f3/32.png) [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Post date:** [January 30, 2021, 8:09pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/8 "2021-01-30T20:09:22Z")

</div>

I'm trying to use kibana as normal.  
It is an Angular script that executes an http post call to 'internal/security/login' attaching username and password as body, and `Content-Type: application/json` and `kbn-xsrf: 7.6.2` as http Header.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [January 30, 2021, 8:26pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/9 "2021-01-30T20:26:24Z")

</div>

So you want to use kibana as normal but you want to skip the login screen?

---

<div class="post-metadata">

**Author:** ![gaetano](https://avatars.discourse-cdn.com/v4/letter/g/b9e5f3/32.png) [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Post date:** [January 30, 2021, 8:55pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/10 "2021-01-30T20:55:46Z")

</div>

> [@mattkime](#):
>
> So you want to use kibana as normal but you want to skip the login screen?

yes my goal would be this. I don't know if it's possible.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [January 30, 2021, 9:01pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/11 "2021-01-30T21:01:31Z")

</div>

Its definitely possible, its just a question of finding the best route since you're potentially creating a significant security hole. Have you considered using SAML authentication? It might provide a nice balance of security and convenience for you - [Authentication in Kibana | Kibana Guide [7.10] | Elastic](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#saml)

---

<div class="post-metadata">

**Author:** ![gaetano](https://avatars.discourse-cdn.com/v4/letter/g/b9e5f3/32.png) [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Post date:** [January 30, 2021, 9:22pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/12 "2021-01-30T21:22:01Z")

</div>

Ok thank you for the attached link.  
Anyway, for info, I tried to access Kibana by first launching the same http post call using the Talend Chrome extension. In that case I was able to access it bypassing the login page and I also noticed that the cookie was set.  
While if I try to launch it via Angular script I am redirected to the login page and the cookie is not set.  
For this reason I wanted to focus my topic on the theme of cookies, as in my opinion the problem had to be addressed and solved in this direction.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [January 30, 2021, 11:43pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/13 "2021-01-30T23:43:18Z")

</div>

If I understand correctly, you're having success with the Talend extension but not your angular script, correct?

Can you share the request and response in each case?

---

<div class="post-metadata">

**Author:** ![gaetano](https://avatars.discourse-cdn.com/v4/letter/g/b9e5f3/32.png) [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Post date:** [February 1, 2021, 8:16am UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/14 "2021-02-01T08:16:19Z")

</div>

TALEND REQUEST - RESPONSE

 ![talend_request](https://us1.discourse-cdn.com/elastic/original/3X/5/5/55a0de6378376f438377fb025722a3ad78a09f09.png)  
 ![talend_request_header](https://us1.discourse-cdn.com/elastic/original/3X/7/a/7af4ebb69c1ef59f907a5d7236e9a6ab3dcf37e6.png)  
 ![talend_response](https://us1.discourse-cdn.com/elastic/original/3X/3/1/31b9e4d3f6a94d41da77085edd5c00f280fab097.png)

SCRIPT REQUEST - RESPONSE

 ![script_request](https://us1.discourse-cdn.com/elastic/original/3X/3/0/301c0aa0f5be7b7456d47a1b98842deb89050f4b.png)  
 ![script_response](https://us1.discourse-cdn.com/elastic/original/3X/c/6/c686594d7e442573d2c6b3cc6ab98aaf5bb0b725.png)  
 ![script_request_header](https://us1.discourse-cdn.com/elastic/original/3X/9/0/90417635ec00f5f8f8ba9f5e55b9b9e9c1429249.png)

---

<div class="post-metadata">

**Author:** ![gaetano](https://avatars.discourse-cdn.com/v4/letter/g/b9e5f3/32.png) [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Post date:** [February 1, 2021, 11:54am UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/15 "2021-02-01T11:54:51Z")

</div>

I would also like to say that I have modified the `http_tools.js` file to enable CORS.  
I inserted  
`cors: {additionalHeaders: ['kbn-version', 'kbn-xsrf', 'cookie'], origin: ['*'], credentials: true},`  
instead of  
`cors: config.cors`

I thought that the problem could be caused by the CORS not enabled.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [February 1, 2021, 6:52pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/16 "2021-02-01T18:52:25Z")

</div>

It looks like you found the solution - [Allow for cookie's `SameSite` attribute to be configurable · Issue #60522 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/60522) - Chrome wants `SameSite=None` to be set which is supported in Kibana v7.8.1

From the requests you shared everything in the request and response is correct.

---

<div class="post-metadata">

**Author:** ![gaetano](https://avatars.discourse-cdn.com/v4/letter/g/b9e5f3/32.png) [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Post date:** [February 2, 2021, 10:09am UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/17 "2021-02-02T10:09:04Z")

</div>

Thank you. I finally decided to install Kibana 7.6.2 on the same domain as my web application. This way I can log into Kibana. The problem in upgrading the **Hapi** library (in Kibana 7.6.2), to enable the use of `SameSite = 'None'`, is very complex. It becomes preferable, at that point, to install a newer version of Kibana.

---

<div class="post-metadata">

**Author:** ![gaetano](https://avatars.discourse-cdn.com/v4/letter/g/b9e5f3/32.png) [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Post date:** [February 3, 2021, 6:25pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/18 "2021-02-03T18:25:15Z")

</div>

Hi, I upgraded Kibana to version 7.10.2.  
I added in `kibana.yml`  
`xpack.security.secureCookies: true`  
`xpack.security.sameSiteCookies: None`  
for the `SameSite` setup, but when I try to access the login page I get this result.

![login](https://us1.discourse-cdn.com/elastic/original/3X/7/6/760b200121027eb1409e8e384fa25972263aa4d4.png)

While on the Cookie section I get this warning:  
**This Set-Cookie was blocked because it had the "Secure" attribute but was not received over a secure connection.**

 ![cookie](https://us1.discourse-cdn.com/elastic/original/3X/2/2/22d2055a9bc76b08df0f2836ce9d27e5233b000a.png)

What changes do I have to make to establish a "secure" connection?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2021, 6:25pm UTC](https://discuss.elastic.co/t/how-to-set-samesite-none-in-kibana-7-6-2/262633/19 "2021-03-03T18:25:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
