# Configuring Access-Control-Allow-Methods response header?

**URL:** <https://discuss.elastic.co/t/configuring-access-control-allow-methods-response-header/7246>\
**Category:** Elasticsearch\
**Created:** [April 5, 2012, 10:29pm UTC](https://discuss.elastic.co/t/configuring-access-control-allow-methods-response-header/7246 "2012-04-05T22:29:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anurag\_Biyani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anurag_biyani/32/2844_2.png) [@Anurag\_Biyani](https://discuss.elastic.co/u/Anurag_Biyani)\
**Post date:** [April 5, 2012, 10:29pm UTC](https://discuss.elastic.co/t/configuring-access-control-allow-methods-response-header/7246/1 "2012-04-05T22:29:50Z")

</div>

I am unable to make an ajax query (POST with contentType: "application/  
json") to elasticsearch server from google-chrome, because elastic  
search seem to return this in response header by default  
Access-Control-Allow-Methods:PUT, DELETE

thus following error is generated:  
XMLHttpRequest cannot load [http://localhost:9200/\_search](http://localhost:9200/_search). Request  
header field Content-Type is not allowed by Access-Control-Allow-  
Headers.

This is similar to issue described here: [https://github.com/elasticsearch/elasticsearch/issues/828](https://github.com/elasticsearch/elasticsearch/issues/828)  
, I was wondering if there is any way now to configure Acess-Control-\*  
headers returned by elastic search.

Thanks!

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [April 7, 2012, 3:38pm UTC](https://discuss.elastic.co/t/configuring-access-control-allow-methods-response-header/7246/2 "2012-04-07T15:38:34Z")

</div>

It would be great if someone could chase down what needs to be returned  
into order to support this, so there won't be a need to configure it  
(unless you want to disable it completely). Seems like the spec has changed  
since last I read it, and it might be different between browsers.

On Fri, Apr 6, 2012 at 1:29 AM, Anurag Biyani [abiyani@dnanexus.com](mailto:abiyani@dnanexus.com) wrote:

> I am unable to make an ajax query (POST with contentType: "application/  
> json") to elasticsearch server from google-chrome, because elastic  
> search seem to return this in response header by default  
> Access-Control-Allow-Methods:PUT, DELETE
> 
> thus following error is generated:  
> XMLHttpRequest cannot load [http://localhost:9200/\_search](http://localhost:9200/_search). Request  
> header field Content-Type is not allowed by Access-Control-Allow-  
> Headers.
> 
> This is similar to issue described here:  
> [Cross-domain (CORS) AJAX woes · Issue #828 · elastic/elasticsearch · GitHub](https://github.com/elasticsearch/elasticsearch/issues/828)  
> , I was wondering if there is any way now to configure Acess-Control-\*  
> headers returned by Elasticsearch.
> 
> Thanks!

---

<div class="post-metadata">

**Author:** ![Anurag\_Biyani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anurag_biyani/32/2844_2.png) [@Anurag\_Biyani](https://discuss.elastic.co/u/Anurag_Biyani)\
**Post date:** [April 9, 2012, 8:53pm UTC](https://discuss.elastic.co/t/configuring-access-control-allow-methods-response-header/7246/3 "2012-04-09T20:53:52Z")

</div>

I am no expert on HTTP CORS myself (hardly a beginner), but my  
interpretation from reading this: [https://developer.mozilla.org/en/http\_access\_control#Preflighted\_requests](https://developer.mozilla.org/en/http_access_control#Preflighted_requests)  
(see end of the section), is that if elasticsearch return these  
headers:

Access-Control-Allow-Methods: POST, GET, PUT, DELETE, OPTIONS  
Access-Control-Allow-Headers: Content-Type

then it should work (since a POST request with content-  
type:application/json is preflighted, and the response header is  
checked for allowed methods). It would be great if someone with  
knowledge of http cors can shed more light on this and propose a more  
generic and encompassing change to Elasticsearch headers.

On Apr 7, 8:38 am, Shay Banon [kim...@gmail.com](mailto:kim...@gmail.com) wrote:

> It would be great if someone could chase down what needs to be returned  
> into order to support this, so there won't be a need to configure it  
> (unless you want to disable it completely). Seems like the spec has changed  
> since last I read it, and it might be different between browsers.
> 
> On Fri, Apr 6, 2012 at 1:29 AM, Anurag Biyani [abiy...@dnanexus.com](mailto:abiy...@dnanexus.com) wrote:
> 
> > I am unable to make an ajax query (POST with contentType: "application/  
> > json") to elasticsearch server from google-chrome, because elastic  
> > search seem to return this in response header by default  
> > Access-Control-Allow-Methods:PUT, DELETE
> 
> > thus following error is generated:  
> > XMLHttpRequest cannot loadhttp://localhost:9200/\_search. Request  
> > header field Content-Type is not allowed by Access-Control-Allow-  
> > Headers.
> 
> > This is similar to issue described here:  
> > [Cross-domain (CORS) AJAX woes · Issue #828 · elastic/elasticsearch · GitHub](https://github.com/elasticsearch/elasticsearch/issues/828)  
> > , I was wondering if there is any way now to configure Acess-Control-\*  
> > headers returned by Elasticsearch.
> 
> > Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:33am UTC](https://discuss.elastic.co/t/configuring-access-control-allow-methods-response-header/7246/4 "2017-07-06T03:33:07Z")

</div>


