# How to use Elasticsearch from a SPA?

**URL:** <https://discuss.elastic.co/t/how-to-use-elasticsearch-from-a-spa/279522>\
**Category:** Elasticsearch\
**Created:** [July 24, 2021, 6:52am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-from-a-spa/279522 "2021-07-24T06:52:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kazza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kazza/32/92044_2.png) [@kazza](https://discuss.elastic.co/u/kazza)\
**Post date:** [July 24, 2021, 6:52am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-from-a-spa/279522/1 "2021-07-24T06:52:10Z")

</div>

I have been wondering what is the best practice when wanting to query Elasticsearch directly from browser javascript. E.g. such as a React/VueJS/Angular application.

I hoped that it would be possible to use a standard oauth token, but from reading the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/oidc-guide.html#oidc-without-kibana) Elasticsearch only supports the Relaying Party role (with the addition of a facilitator service account) and not a Resource Server role. This causes a number of issues with a typical SPA architecture, which normally its self would be the Relaying Party/Client.

I was thinking that there are two options:

1. Create a back end API that queries Elasticsearch and returns the results to the browser. This feels like a waste of effort, but would work and be more secure.
2. Allow anonymous read access to specific indices. This is sub optimal as its not always the case that anonymous access is acceptable.

Is there a better solution?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 26, 2021, 7:48am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-from-a-spa/279522/2 "2021-07-26T07:48:38Z")

</div>

From a security perspective you should consider Elasticsearch the same as a SQL database (think MySQL and Postgres), which also should not be exposed to the internet at any time.

The middleware you are talking in between is IMO a good additional security layer, as you can write the search queries on that component instead of just accepting blindly any user supplied JSON (that could contain arbitrary complex queries).  
Also, such a middleware would allow you later on, to modify the query without the user noticing - think of boosting search results you get a higher commission on.

Hope this helps as a start.

---

<div class="post-metadata">

**Author:** ![kazza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kazza/32/92044_2.png) [@kazza](https://discuss.elastic.co/u/kazza)\
**Post date:** [July 26, 2021, 8:11am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-from-a-spa/279522/3 "2021-07-26T08:11:22Z")

</div>

Thanks, you make some good points 🙂

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 26, 2021, 12:23pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-from-a-spa/279522/4 "2021-07-26T12:23:19Z")

</div>

Oh, one more thing. You might want to take a look at [Elastic App Search](https://www.elastic.co/app-search/), which is exactly providing a simplified middleware already and also allows you to access that middleware directly via the browser. You can try that out via Elastic Cloud, or give it a test run locally!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2021, 12:24pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-from-a-spa/279522/5 "2021-08-23T12:24:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
