# Websocket authentication

**URL:** <https://forums.suse.com/t/websocket-authentication/12219>\
**Category:** SUSE Rancher Prime\
**Created:** [November 1, 2018, 12:37pm UTC](https://forums.suse.com/t/websocket-authentication/12219 "2018-11-01T12:37:42Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Seralto](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/seralto/32/4594_2.png) [@Seralto](https://forums.suse.com/u/Seralto)\
**Post date:** [November 1, 2018, 12:37pm UTC](https://forums.suse.com/t/websocket-authentication/12219/1 "2018-11-01T12:37:42Z")

</div>

I am trying to connect in a websocket via browser (javascript) in order to consume a Log and I am having no success. The error message is `HTTP Authentication failed; no valid credentials available`.

I already generate a token and when I test it via Postman I can connect using `Authorizatior Bearer <token>`.

I tried inserting the token in the URL:  
`wss://token-xxxxx:xxxxxxxxxxxxxxxxxxx@rancher.tks.sh...`

As a query parameter:  
`wss://rancher.tks.sh...&token=token-xxxxx:xxxxxxxxxxxxxxxxxxx`

Inside the connection:  
`new WebSocket(`wss://rancher.tks.sh…`, ['access_token', token=token-xxxxx:xxxxxxxxxxxxxxxxxxx'']);`

And none of these approaches has succeeded.

Just to mention, if I am logged-in in another tab in Rancher, I can consume the log, but probably because the browser send the cookies with the authorization.

Anyone can help?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [November 1, 2018, 10:13pm UTC](https://forums.suse.com/t/websocket-authentication/12219/2 "2018-11-01T22:13:34Z")

</div>

Browsers don’t send basic auth to the server (`wss://token-...:...@host` is just ignored), and the server does not accept a token anywhere other than the Authorization header (the rest).

It also should be verifying that the Origin header is the same as the Host header, so even if you had a way to pass valid credentials just opening a socket to a different domain won’t work. And for HTTP requests there’s no CORS headers sent…

Generally talking directly from one origin to the API on another is not a common practice. Proxy requests through your own domain; we do similar for UI development: [https://github.com/rancher/ui/blob/master/server/proxies/api.js](https://github.com/rancher/ui/blob/master/server/proxies/api.js)

---

<div class="post-metadata">

**Author:** ![Seralto](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/seralto/32/4594_2.png) [@Seralto](https://forums.suse.com/u/Seralto)\
**Post date:** [November 6, 2018, 5:26pm UTC](https://forums.suse.com/t/websocket-authentication/12219/3 "2018-11-06T17:26:33Z")

</div>

Thanks Vincent for your help.

---

<div class="post-metadata">

**Author:** ![alfrye](https://avatars.discourse-cdn.com/v4/letter/a/bbce88/32.png) [@alfrye](https://forums.suse.com/u/alfrye)\
**Post date:** [November 8, 2018, 2:45pm UTC](https://forums.suse.com/t/websocket-authentication/12219/4 "2018-11-08T14:45:52Z")

</div>

I have similar question! I am trying to access the Rancher 2.0 api from a web application in another domain and I am getting cors errors. I was able to get an ingress that sets the cors headers when trying to access web server that I created and deployed to the cluster. However, I am not sure how to configure an ingress for allow cors when trying to access the Rancher API.
