# Minimal security but CORS handling

**URL:** <https://discuss.elastic.co/t/minimal-security-but-cors-handling/347426>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [November 17, 2023, 6:27pm UTC](https://discuss.elastic.co/t/minimal-security-but-cors-handling/347426 "2023-11-17T18:27:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![javerleo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/javerleo/32/127698_2.png) [@javerleo](https://discuss.elastic.co/u/javerleo)\
**Post date:** [November 17, 2023, 6:27pm UTC](https://discuss.elastic.co/t/minimal-security-but-cors-handling/347426/1 "2023-11-17T18:27:11Z")

</div>

Hello.

I'm trying to set up a local Elasticsearch instance for development purposes. So I started with a basic docker-compose.yml file:

```auto
services:

  elasticsearch:
    image: elasticsearch:8.7.1
    ports:
      - 9200:9200
    environment:
      discovery.type: single-node # Runs as a single-node
      ES_JAVA_OPTS: '-Xms256m -Xmx256m'
      network.bind_host: 0.0.0.0
      xpack.security.enabled: 'false'
    volumes: # Stores elasticsearch data locally on the esdata Docker volume
      - esdata:/usr/share/elasticsearch/data
    networks:
      - internal
      - elastic

# Define the Docker volume named esdata for the Elasticsearch container.
volumes:
  esdata:
# Networks to use
networks:
  elastic:
    external: true
  internal:
    driver: bridge

```

This works fine, in order to test a WordPress plugin that uses Elasticsearch. However, Now I need to avoid CORS related errors, so I tried to add parameters to the environment:

```auto
      http.cors.enabled: 'true'
      http.cors.allow-origin: "*"
      http.cors.allow-methods: OPTIONS, HEAD, GET, POST, PUT, DELETE
      http.cors.allow-headers: X-Requested-With, X-Auth-Token, Content-Type, Content-Length, Authorization, Access-Control-Allow-Headers, Accept
      http.cors.allow-credentials: 'true'

```

This doesn't work. The Elasticsearch refuses connections after applying the changes.

So, what I need is to have the same minimal security but allowing at the same time CORS request from anywhere.

Your suggestions will be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2023, 6:27pm UTC](https://discuss.elastic.co/t/minimal-security-but-cors-handling/347426/2 "2023-12-15T18:27:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
