# Kibana 7.12.0 server.cors setting seems not work

**URL:** <https://discuss.elastic.co/t/kibana-7-12-0-server-cors-setting-seems-not-work/309561>\
**Category:** Kibana\
**Tags:** kibana-plugin-development\
**Created:** [July 13, 2022, 5:01pm UTC](https://discuss.elastic.co/t/kibana-7-12-0-server-cors-setting-seems-not-work/309561 "2022-07-13T17:01:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Terry\_Li](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/terry_li/32/82551_2.png) [@Terry\_Li](https://discuss.elastic.co/u/Terry_Li)\
**Post date:** [July 13, 2022, 5:01pm UTC](https://discuss.elastic.co/t/kibana-7-12-0-server-cors-setting-seems-not-work/309561/1 "2022-07-13T17:01:46Z")

</div>

Hi, I need to login Kibana via my application ("[http://localhost:3000](http://localhost:3000)"). I post login data to "[http://localhost:5601/internal/security/login](http://localhost:5601/internal/security/login)" by ajax, but "Access-Control-Allow-Origin" header not show in the response

```auto
$.ajax({
  url: "http://localhost:5601/internal/security/login",
  method: "POST",
  dataType: "json",
  headers: {
    "Content-Type": "application/json",
    "kbn-version": "7.12.0",
    "kbn-xsrf": "7.12.0",
    "Access-Control-Allow-Origin": "*",
    "Access-Control-Allow-Credentials": true,
    "Access-Control-Allow-Methods": "*",
    "Access-Control-Allow-Headers": "*"
  },
  data: {
    params: {username: "admin", password: "admin"},
    provideName: "basic",
    provideType: "basic",
  }
});

```

-kibana.yml

```auto
server.cors.enabled: true
server.cors.allowCredentials: true
server.cors.allowOrigin: ["http://localhost:3000"]

```

-elasticsearch.yml

```auto
http.cors.enabled: true
http.cors.allow-origin: "*"
http.cors.allow-credentials: true
http.cors.allow-methods: OPTIONS,HEAD,GET,POST,PUT,DELETE
http.cors.allow-headers: kbn-version,kbn-xsrf,Origin,X-Requested-With,Content-Type,Accept,Engaged-Auth-Token,Content-Length,Authorization

```

Response to OPTIONS request (kibana -\> client)

```auto
HTTP/1.1 200 OK
cache-control: private, no-cache, no-store, must-revalidate
Connection: keep-alive
content-length: 54
content-type: application/json; charset=utf-8
Date: Wed, 13 Jul 2022 16:52:45 GMT
kbn-license-sig:...
kbn-name: kibana
Keep-Alive: timeout=120

```

Why server.cors.allowOrigin setting not work?  
Thank you.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [July 15, 2022, 2:57pm UTC](https://discuss.elastic.co/t/kibana-7-12-0-server-cors-setting-seems-not-work/309561/2 "2022-07-15T14:57:09Z")

</div>

Hi Terry,

I don't know much about cors but found this which might help;

> <https://github.com/elastic/kibana/issues/1316>
>
> I am trying to configure kibana to use HTTP basic auth when making requests to E…S.
> 
> My kibana config.json:
> 
> \`\`\`
> elasticsearch: {server: "http://example.com:9200", withCredentials: true}
> \`\`\`
> 
> Results in this error in Chrome Dev Tools:
> 
> \`\`\`
> XMLHttpRequest cannot load http://example.com:9200/\_nodes. A wildcard '\*' cannot be used in the 'Access-Control-Allow-Origin' header when the credentials flag is true. Origin 'http://example.com' is therefore not allowed access.
> \`\`\`

Please let us know if you find your solution so others can learn as well.

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 12, 2022, 2:57pm UTC](https://discuss.elastic.co/t/kibana-7-12-0-server-cors-setting-seems-not-work/309561/3 "2022-08-12T14:57:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
