# Config cors setting not working?

**URL:** <https://discuss.elastic.co/t/config-cors-setting-not-working/90189>\
**Category:** Elasticsearch\
**Created:** [June 21, 2017, 2:25am UTC](https://discuss.elastic.co/t/config-cors-setting-not-working/90189 "2017-06-21T02:25:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gordon\_Wang](https://avatars.discourse-cdn.com/v4/letter/g/e495f1/32.png) [@Gordon\_Wang](https://discuss.elastic.co/u/Gordon_Wang)\
**Post date:** [June 21, 2017, 2:25am UTC](https://discuss.elastic.co/t/config-cors-setting-not-working/90189/1 "2017-06-21T02:25:01Z")

</div>

I setup a standalone elasticsearch using docker image(elasticsearch:alpine)  
Try to enable cors setting in /usr/share/elasticsearch/config/elasticsearch.yml

```auto
http.cors.enabled: true
http.cors.allow-origin: "*"
http.cors.allow-methods: OPTIONS, HEAD, GET, POST, PUT, DELETE
http.cors.allow-headers: "X-Requested-With,X-Auth-Token,Content-Type, Content-Length, Authorization"

```

then restart this container.  
curl --head [http://localhost:9200](http://localhost:9200), the result is

```auto
HTTP/1.1 200 OK
content-type: application/json; charset=UTF-8
content-length: 327

```

No CORS header, is it right?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 23, 2017, 6:34am UTC](https://discuss.elastic.co/t/config-cors-setting-not-working/90189/2 "2017-06-23T06:34:59Z")

</div>

> [@Gordon\_Wang](#):
>
> No CORS header, is it right?

CORS is a two-way process. The client sends particular CORS-related headers, and then the server responds appropriately. Unless you tell `curl` to set those request headers, you won't see anything in the response.

If you add the `Origin` header to your request, you should see what you're looking for:

```
$ curl --head http://localhost:9200 -H 'Origin: http://foo.com'

HTTP/1.1 200 OK
access-control-allow-origin: *
content-type: application/json; charset=UTF-8
content-length: 326

```

---

<div class="post-metadata">

**Author:** ![Gordon\_Wang](https://avatars.discourse-cdn.com/v4/letter/g/e495f1/32.png) [@Gordon\_Wang](https://discuss.elastic.co/u/Gordon_Wang)\
**Post date:** [June 26, 2017, 1:39am UTC](https://discuss.elastic.co/t/config-cors-setting-not-working/90189/3 "2017-06-26T01:39:58Z")

</div>

Thanks. my negligenc...

---

<div class="post-metadata">

**Author:** ![Yugansh\_Aggarwal](https://avatars.discourse-cdn.com/v4/letter/y/9fc29f/32.png) [@Yugansh\_Aggarwal](https://discuss.elastic.co/u/Yugansh_Aggarwal)\
**Post date:** [July 7, 2017, 12:53pm UTC](https://discuss.elastic.co/t/config-cors-setting-not-working/90189/4 "2017-07-07T12:53:09Z")

</div>

Thanks a lot...That helped me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 4, 2017, 12:53pm UTC](https://discuss.elastic.co/t/config-cors-setting-not-working/90189/5 "2017-08-04T12:53:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
