# Kibana iframe working due to cookies attribute "SameSite"

**URL:** <https://discuss.elastic.co/t/kibana-iframe-working-due-to-cookies-attribute-samesite/225326>\
**Category:** Kibana\
**Created:** [March 27, 2020, 4:05am UTC](https://discuss.elastic.co/t/kibana-iframe-working-due-to-cookies-attribute-samesite/225326 "2020-03-27T04:05:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rebirther](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rebirther/32/19228_2.png) [@rebirther](https://discuss.elastic.co/u/rebirther)\
**Post date:** [March 27, 2020, 4:05am UTC](https://discuss.elastic.co/t/kibana-iframe-working-due-to-cookies-attribute-samesite/225326/1 "2020-03-27T04:05:28Z")

</div>

At moment, Kibana refuses to work in newer versions of browsers for iframe (for example for Chrome 80.0.3987.149). Is there any way on the Kibana side to set cookies attributes - "SameSite=None" and "Secure"?

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [March 27, 2020, 10:22am UTC](https://discuss.elastic.co/t/kibana-iframe-working-due-to-cookies-attribute-samesite/225326/2 "2020-03-27T10:22:54Z")

</div>

You can turn on the secure flag using the `xpack.security.secureCookies` setting.

[https://www.elastic.co/guide/en/kibana/current/security-settings-kb.html](https://www.elastic.co/guide/en/kibana/current/security-settings-kb.html)

`SameSite` can't be set right now, here is the issue to track the fix: [https://github.com/elastic/kibana/issues/60522](https://github.com/elastic/kibana/issues/60522) - the issue also lists a workaround for the problem.

---

<div class="post-metadata">

**Author:** ![rebirther](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rebirther/32/19228_2.png) [@rebirther](https://discuss.elastic.co/u/rebirther)\
**Post date:** [March 27, 2020, 3:09pm UTC](https://discuss.elastic.co/t/kibana-iframe-working-due-to-cookies-attribute-samesite/225326/3 "2020-03-27T15:09:55Z")

</div>

> [@flash1293](#):
>
> `SameSite` can't be set right now, here is the issue to track the fix: [Allow for cookie's `SameSite` attribute to be configurable · Issue #60522 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/60522) - the issue also lists a workaround for the problem.

Thank you, I saw it, but it seems there is no answer from Kibana developers.  
And I'm sorry, but I did not see workarounds in problem there.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [March 27, 2020, 3:15pm UTC](https://discuss.elastic.co/t/kibana-iframe-working-due-to-cookies-attribute-samesite/225326/4 "2020-03-27T15:15:33Z")

</div>

No worries!

As a side note: The issue was originally created by a Kibana developer - it's difficult to see on Github, when you are hovering over a name it says `Member of elastic`:  
 ![Screenshot 2020-03-27 at 16.14.50](https://us1.discourse-cdn.com/elastic/original/3X/2/9/29de5db148e5debcd9ca97054c4a0fc632920b50.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2020, 3:15pm UTC](https://discuss.elastic.co/t/kibana-iframe-working-due-to-cookies-attribute-samesite/225326/5 "2020-04-24T15:15:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
