# Kibana Iframe Share Issue with Xframe and SameSite Cookie

**URL:** <https://discuss.elastic.co/t/kibana-iframe-share-issue-with-xframe-and-samesite-cookie/316824>\
**Category:** Kibana\
**Created:** [October 17, 2022, 8:09pm UTC](https://discuss.elastic.co/t/kibana-iframe-share-issue-with-xframe-and-samesite-cookie/316824 "2022-10-17T20:09:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![hidanny](https://avatars.discourse-cdn.com/v4/letter/h/22d042/32.png) [@hidanny](https://discuss.elastic.co/u/hidanny)\
**Post date:** [October 17, 2022, 8:09pm UTC](https://discuss.elastic.co/t/kibana-iframe-share-issue-with-xframe-and-samesite-cookie/316824/1 "2022-10-17T20:09:06Z")

</div>

Hello all,

This may be a super dumb question. For reference, I am using latest React and Google Chrome. Also, to note, this is working completely fine in Firefox. Just not in Google Chrome.

Essentially, I am trying to display a Kibana's Iframe on my local React website.  
The problem is that its giving me **Refused to display '[https://federate-prod-es](https://federate-prod-es)...company.com" in a frame because it set "X-Frame-Options" to "deny"**

Another issue that I can see when tracking the cookies is that I see "SameSite" cookie is giving a Lax instead of None.

Does this mean that I should Install Kibana to get the Kibana.yaml to edit these properties? I thought I would be able to just easily embed the shared results of Kibana on my site.

What can I do to resolve this? Am I not understanding something?

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [October 24, 2022, 12:49pm UTC](https://discuss.elastic.co/t/kibana-iframe-share-issue-with-xframe-and-samesite-cookie/316824/2 "2022-10-24T12:49:34Z")

</div>

The kibana yaml setting you are likely looking for is `xpack.security.sameSiteCookies`, more details [hele](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#embedded-content-authentication).

I've just added it to my Elastic Cloud deployment

![image](https://us1.discourse-cdn.com/elastic/original/3X/f/9/f9cdfe018b423cd8c8e54910727a7f7c39a43c83.png)

And I could deploy a minimal TypeScript React application that shows an iframe of a public dashboard I have at [https://ela.st/cumbre-vieja-eruption](https://ela.st/cumbre-vieja-eruption) on this location: [https://ihbdnn.csb.app/](https://ihbdnn.csb.app/)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/c/2c2f7c7b79c585a8544c9855f77b61e9d8c3a1f8.jpeg)

Mind that of course one thing is allowing your iframe to load and another for Kibana to display stuff for anonymous users, skip the login screen and so on. The whole [Anonymous authentication](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#anonymous-authentication) section in the Kibana docs provides comprehensive details on how this works.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2022, 8:04pm UTC](https://discuss.elastic.co/t/kibana-iframe-share-issue-with-xframe-and-samesite-cookie/316824/3 "2022-11-19T20:04:39Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 17, 2022, 4:54pm UTC](https://discuss.elastic.co/t/kibana-iframe-share-issue-with-xframe-and-samesite-cookie/316824/4 "2022-12-17T16:54:55Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2023, 1:08pm UTC](https://discuss.elastic.co/t/kibana-iframe-share-issue-with-xframe-and-samesite-cookie/316824/5 "2023-01-14T13:08:59Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2023, 1:09pm UTC](https://discuss.elastic.co/t/kibana-iframe-share-issue-with-xframe-and-samesite-cookie/316824/6 "2023-02-11T13:09:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
