# Single page appliaction (SPA) using Elasticsearch REST APIs

**URL:** <https://discuss.elastic.co/t/single-page-appliaction-spa-using-elasticsearch-rest-apis/329735>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [April 11, 2023, 10:52am UTC](https://discuss.elastic.co/t/single-page-appliaction-spa-using-elasticsearch-rest-apis/329735 "2023-04-11T10:52:48Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![gichhr](https://avatars.discourse-cdn.com/v4/letter/g/ea666f/32.png) [@gichhr](https://discuss.elastic.co/u/gichhr)\
**Post date:** [April 11, 2023, 10:52am UTC](https://discuss.elastic.co/t/single-page-appliaction-spa-using-elasticsearch-rest-apis/329735/1 "2023-04-11T10:52:48Z")

</div>

Hello,

I'd like to confirm that can be generated a React static Single Page Application (SPA) that use Elasticsearch REST APIs for authentication and role authorization and queering data form indexes. This static SPA can be hosted for example in AWS S3. All communication to elasticsearch will be through REST APIs.

For example for authentication can be used "\_security/oauth2/token" sending grant\_type, username and password and obtaining access\_token, refresh token and roles. Having the token can be used for queering the indexes.

Is that possible and recommended? Are there security issues that I'm missing?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2023, 10:53am UTC](https://discuss.elastic.co/t/single-page-appliaction-spa-using-elasticsearch-rest-apis/329735/2 "2023-05-09T10:53:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
