# Why session authentication always fails?

**URL:** https://discuss.elastic.co/t/why-session-authentication-always-fails/123738
**Category:** Kibana
**Created:** [March 13, 2018, 1:31pm UTC](https://discuss.elastic.co/t/why-session-authentication-always-fails/123738 "2018-03-13T13:31:18Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![ahrtr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahrtr/32/29551_2.png) [@ahrtr](https://discuss.elastic.co/u/ahrtr)
#### Post date: [March 13, 2018, 1:31pm UTC](https://discuss.elastic.co/t/why-session-authentication-always-fails/123738/1 "2018-03-13T13:31:18Z")

</div>

I am trying to implement a kibana plugin to protect kibana. If a user hasn't logged in, then the page will be redirected to the login page. But the issue is that the page is always redirected to the login page, even the user has logged in sucessfully.

The code is something like below,

File 1: route.js.

```
......
    server.route({
        method: 'POST',
        path: '/auth/login',
        handler: {
            async: async (request, reply) => {
                if (request.payload.username === 'admin' && request.payload.password === 'changeme') {

                    var credentials = {"username": request.payload.username, "password": request.payload.password};

                    let myCookie = {
                        username: request.payload.username,
                        credentials: credentials
                    };

                    myCookie.expiryTime = Date.now() + 3600000;

                    request.cookieAuth.set(myCookie);

                    return replay({
                        username: request.payload.username
                    })
                }
                else {
                    return reply(Boom.unauthorized('Invalid username or password'));
                }
            }
        },
        config: {
            validate: {
                payload: {
                    username: Joi.string().required(),
                    password: Joi.string().required()
                }
            },
            auth: false
        }
    });
......

```

File 2: auth.js. It seems that the "server.auth.test" always fails, so the page is always redirected to the login page. Can anyone point out what's the root cause? Thanks.

```
......
    const cookieConfig = {
      password: 'fake_password_12345_to_protect_cookie',
      cookie: 'example_cookie',
      isSecure: true,
      validateFunc: pluginRoot('server/session/validate')(server),
      ttl: 60 * 60 * 1000
    };

    server.auth.strategy('access_control_cookie', 'cookie', false, cookieConfig);

    server.auth.scheme('access_control_scheme', (server, options) => ({
        authenticate: (request, reply) => {
            server.auth.test('access_control_cookie', request, (error, credentials) => {                
                if (error) {
                    const nextUrl = encodeURIComponent(request.url.path);
                    return reply.redirect(`${basePath}/login?nextUrl=${nextUrl}`);
                }
                reply.continue({credentials});
            });
        }
    }));

    server.auth.strategy('access_control', 'access_control_scheme', true);
......

```

File 3: validate.js

```
......
    export default function (server) {
      return function validate(request, session, callback) {
        try {
            if (!session.expiryTime || session.expiryTime < Date.now()) {
                return callback(new InvalidSessionError('Session expired.'), false);
            }
            
            if (session.credentials.username === 'admin' && session.credentials.password === 'password') {
                let extendedSession = {};
                assign(extendedSession, session);
                extendedSession.expiryTime = Date.now() + 3600000;
                request.cookieAuth.set(session);

                return callback(null, true, user);
            } 
            else {
                return callback(new InvalidSessionError('Invalid session.', error), false);
            }

        } catch (error) {
            return callback(new InvalidSessionError('Invalid session', error), false);
        }
      };
    };
......
```

---

<div class="post-metadata">

### Author: ![ahrtr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahrtr/32/29551_2.png) [@ahrtr](https://discuss.elastic.co/u/ahrtr)
#### Post date: [March 14, 2018, 12:17am UTC](https://discuss.elastic.co/t/why-session-authentication-always-fails/123738/2 "2018-03-14T00:17:09Z")

</div>

> [@ahrtr](#):
>
> const cookieConfig = {  
> password: 'fake\_password\_12345\_to\_protect\_cookie',  
> cookie: 'example\_cookie',  
> isSecure: true,  
> validateFunc: pluginRoot('server/session/validate')(server),  
> ttl: 60 \* 60 \* 1000  
> };

Finally I realize that I configured a wrong value for "isSecure". Currently I am using HTTP, so it should be configured as "false" for now.

---

<div class="post-metadata">

### Author: ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)
#### Post date: [March 14, 2018, 3:57am UTC](https://discuss.elastic.co/t/why-session-authentication-always-fails/123738/3 "2018-03-14T03:57:23Z")

</div>

Glad you figured it out!

---

<div class="post-metadata">

### Author: ![ahrtr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahrtr/32/29551_2.png) [@ahrtr](https://discuss.elastic.co/u/ahrtr)
#### Post date: [March 14, 2018, 8:21am UTC](https://discuss.elastic.co/t/why-session-authentication-always-fails/123738/4 "2018-03-14T08:21:47Z")

</div>

hi @spalger, thanks anyway.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 11, 2018, 8:22am UTC](https://discuss.elastic.co/t/why-session-authentication-always-fails/123738/5 "2018-04-11T08:22:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
