-
Notifications
You must be signed in to change notification settings - Fork 1.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CORS No 'Access-Control-Allow-Origin' header is present #1421
Comments
To understand why cors doesn't work for your specific case, set |
I got
But https://www.ory.sh/docs/hydra/configuration says
|
And why doesn't "SERVE_PUBLIC_CORS_DEBUG=1" work
But https://www.ory.sh/docs/hydra/configuration says
|
Yeah that was broken on master and has been resolved with fa10d9d which has not been released as a new version yet. |
Try setting:
|
Thank you it works. |
where to set `CORS_DEBUG ?? |
Got same error while integrating my REST API with my react frontend.. any solution please?? |
Describe the bug
When trying to do authorization code grant with PKCE on a SPA(Single Page Application),
I get this error in Chromium when trying to access http://localhost:4444/oauth2/token with ajax
To Reproduce
I have a hydra instance running on
http://localhost:4444
and a client(SPA) on porthttp://localhost:4200
.I have set the environment variables:
SERVE_PUBLIC_CORS_ENABLED=true
andSERVE_PUBLIC_CORS_ALLOWED_ORIGINS=
And registered a client with
I go to:
http://localhost:4444/oauth2/auth?response_type=code&scope=openid&client_id=16719cc1-6087-44b0-9d60-453c3b7eddae&code_challenge_method=S256&code_challenge=djnDoN2i-IqEUoaXDtUMJfa2Zw-i9kPtFDZ5wGOi-2g&redirect_uri=http%3A%2F%2Flocalhost%3A4200%2Fcallback&state=12345678
I do the login, consent flow
The client(SPA) when it gets the code:
Steps to reproduce the behavior:
some-command
Expected behavior
For CORS to not block
Screenshots
data:image/s3,"s3://crabby-images/37fd6/37fd64d6d7882761f6a86ecca5df999d84a681ad" alt="image"
If applicable, add screenshots to help explain your problem.
Version:
Additional context
Add any other context about the problem here.
The text was updated successfully, but these errors were encountered: