# Login API CORS issue with localhost

**URL:** <https://discuss.elastic.co/t/login-api-cors-issue-with-localhost/94528>\
**Category:** Kibana\
**Created:** [July 25, 2017, 6:24pm UTC](https://discuss.elastic.co/t/login-api-cors-issue-with-localhost/94528 "2017-07-25T18:24:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sannj](https://avatars.discourse-cdn.com/v4/letter/s/f475e1/32.png) [@Sannj](https://discuss.elastic.co/u/Sannj)\
**Post date:** [July 25, 2017, 6:24pm UTC](https://discuss.elastic.co/t/login-api-cors-issue-with-localhost/94528/1 "2017-07-25T18:24:51Z")

</div>

Hi, we are working with elastic search and kibana.  
We have them on different servers. We need to embed the kibana dashboard in an iframe in our react page.  
We are trying to auto-login by making an API call (`/api/security/v1/login`) to the kibana server but then we are getting this issue:  
`Fetch API cannot load http://10.33.178.146:5601/api/security/v1/login. Response to preflight request doesn't pass access control check: No 'Access-Control-Allow-Origin' header is present on the requested resource. Origin 'http://localhost:3000' is therefore not allowed access. If an opaque response serves your needs, set the request's mode to 'no-cors' to fetch the resource with CORS disabled.`  
We have set:

````auto
http.cors.allow-origin: "/.*/"
http.cors.allow-credentials: true```
in elasticsearch.yml
and also:
```server.cors: true
server.cors.origin: "/.*/"```
in kibana.yml and we are still getting the same error when we run the code on our localhost.
We also tried `http.cors.allow-origin: "*"` and `server.cors.origin: "*"` and it didn't work. :(
Is there something we are missing?

These are the headers we are setting when we make the HTTP POST call:
```"Content-Type": "multipart/form-data",
          "Content-Length": Buffer.byteLength(body),
          "kbn-version": "5.5.0"```

P.S: It works fine with postman.
````

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [July 26, 2017, 11:52am UTC](https://discuss.elastic.co/t/login-api-cors-issue-with-localhost/94528/2 "2017-07-26T11:52:31Z")

</div>

I believe you want server.cors.origin to be an array.

If you want any origin, `server.cors.origin: ['*']`

We're using hapi behind the scenes here (defaulted to off). For reference, the cors object under [https://hapijs.com/api/14.2.0#route-configuration](https://hapijs.com/api/14.2.0#route-configuration). I don't see this documented on our site so let me know if that works for you and I'll get a fix up.

---

<div class="post-metadata">

**Author:** ![Sannj](https://avatars.discourse-cdn.com/v4/letter/s/f475e1/32.png) [@Sannj](https://discuss.elastic.co/u/Sannj)\
**Post date:** [July 26, 2017, 2:06pm UTC](https://discuss.elastic.co/t/login-api-cors-issue-with-localhost/94528/3 "2017-07-26T14:06:32Z")

</div>

I have tried that too and it didn't work 😔

---

<div class="post-metadata">

**Author:** ![Sannj](https://avatars.discourse-cdn.com/v4/letter/s/f475e1/32.png) [@Sannj](https://discuss.elastic.co/u/Sannj)\
**Post date:** [July 27, 2017, 8:58pm UTC](https://discuss.elastic.co/t/login-api-cors-issue-with-localhost/94528/4 "2017-07-27T20:58:56Z")

</div>

This issue got fixed by adding:  
`cors: { additionalHeaders: ['kbn-version','cookie'], origin: ['*'] },`  
to  
`kibana/src/server/http/setup_connection.js`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2017, 8:59pm UTC](https://discuss.elastic.co/t/login-api-cors-issue-with-localhost/94528/5 "2017-08-24T20:59:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
