# CORS Error while using the Elastic Enterprise Search

**URL:** <https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601>\
**Category:** Elastic Search\
**Tags:** docker\
**Created:** [February 8, 2021, 1:00pm UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601 "2021-02-08T13:00:02Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![anuragchoudhary01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anuragchoudhary01/32/83611_2.png) [@anuragchoudhary01](https://discuss.elastic.co/u/anuragchoudhary01)\
**Post date:** [February 8, 2021, 1:00pm UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601/1 "2021-02-08T13:00:03Z")

</div>

Hi,

I have deployed the Enterprise Search using docker and when I am trying to access it, using react-js client(@elastic/search-ui-app-search-connector). I am getting CORS Error as the URL for both are different.

Just like, elasticsearch is there any way to pass the list of URLs to the Access-Control-Allow-Origin ?

---

<div class="post-metadata">

**Author:** ![orhantoy](https://avatars.discourse-cdn.com/v4/letter/o/c5a1d2/32.png) [@orhantoy](https://discuss.elastic.co/u/orhantoy)\
**Post date:** [February 8, 2021, 1:05pm UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601/2 "2021-02-08T13:05:42Z")

</div>

Hi 👋 Enterprise Search does allow CORS requests to the App Search API from any origin. What endpoints/APIs are you seeing errors from?

---

<div class="post-metadata">

**Author:** ![anuragchoudhary01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anuragchoudhary01/32/83611_2.png) [@anuragchoudhary01](https://discuss.elastic.co/u/anuragchoudhary01)\
**Post date:** [February 8, 2021, 1:26pm UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601/3 "2021-02-08T13:26:20Z")

</div>

Hi @orhantoy,

I am getting the below error.

**An unexpected error occurred: Origin [https://staging.ui.xyz.com](https://staging.ui.xyz.com) is not allowed by Access-Control-Allow-Origin.**

My App Search URL is - [https://staging.appsearch.xyz.com/](https://staging.appsearch.xyz.com/)

ReactJs - @elastic/search-ui-app-search-connector

React Component is Creating this URL - [https://staging.appsearch.xyz.com/api/as/v1/engines/blahblah/search.json](https://staging.appsearch.xyz.com/api/as/v1/engines/blahblah/search.json)

---

<div class="post-metadata">

**Author:** ![anuragchoudhary01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anuragchoudhary01/32/83611_2.png) [@anuragchoudhary01](https://discuss.elastic.co/u/anuragchoudhary01)\
**Post date:** [February 8, 2021, 1:48pm UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601/4 "2021-02-08T13:48:31Z")

</div>

Error:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b54df844c6933cb3200098b4a97f067a1512e3a5.png)

---

<div class="post-metadata">

**Author:** ![orhantoy](https://avatars.discourse-cdn.com/v4/letter/o/c5a1d2/32.png) [@orhantoy](https://discuss.elastic.co/u/orhantoy)\
**Post date:** [February 8, 2021, 3:08pm UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601/5 "2021-02-08T15:08:59Z")

</div>

What version of App/Enterprise Search are you using?

Also, can I get you to perform a [preflight request](https://developer.mozilla.org/en-US/docs/Glossary/Preflight_request) to the API and tell what CORS headers are being returned?

---

<div class="post-metadata">

**Author:** ![anuragchoudhary01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anuragchoudhary01/32/83611_2.png) [@anuragchoudhary01](https://discuss.elastic.co/u/anuragchoudhary01)\
**Post date:** [February 8, 2021, 3:31pm UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601/6 "2021-02-08T15:31:14Z")

</div>

enterprise-search:7.10.2 is the one, I am using.

**Headers:**

```
OPTIONS /api/as/v1/engines/blahblah/search.json HTTP/1.1
Host: staging.appsearch.xyz.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:85.0) Gecko/20100101 Firefox/85.0
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Access-Control-Request-Method: POST
Access-Control-Request-Headers: authorization,content-type,x-swiftype-client,x-swiftype-client-version,x-swiftype-integration,x-swiftype-integration-version
Referer: https://staging.ui.xyz.com/blahblah/search
Origin: https://staging.ui.xyz.com
Connection: keep-alive
```

---

<div class="post-metadata">

**Author:** ![orhantoy](https://avatars.discourse-cdn.com/v4/letter/o/c5a1d2/32.png) [@orhantoy](https://discuss.elastic.co/u/orhantoy)\
**Post date:** [February 8, 2021, 5:48pm UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601/7 "2021-02-08T17:48:39Z")

</div>

Can you see the response to that request? More specifically, I'm interested in the CORS-related response headers.

---

<div class="post-metadata">

**Author:** ![anuragchoudhary01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anuragchoudhary01/32/83611_2.png) [@anuragchoudhary01](https://discuss.elastic.co/u/anuragchoudhary01)\
**Post date:** [February 9, 2021, 6:22am UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601/8 "2021-02-09T06:22:14Z")

</div>

Please find below the response:

```
HTTP/1.1 200 OK
date: Tue, 09 Feb 2021 06:20:17 GMT
allow: GET,HEAD,POST,OPTIONS
server: Jetty(9.4.30.v20200611)
access-control-allow-credentials: true
access-control-allow-origin: https://staging.ui.xyz.com
access-control-allow-headers: x-swiftype-client, x-swiftype-client-version, x-swiftype-integration, x-swiftype-integration-version, Origin, X-Requested-With, Content-Type, Accept, Authorization, JSNLog-RequestId, activityId, applicationId, applicationUserId, channelId, senderId, sessionId, X-Forwarded-Proto, DNT, X-CustomHeader, Keep-Alive, User-Agent, If-Modified-Since, Cache-Control, Content-Range, Range, X-Auth-Token
access-control-max-age: 3628800
access-control-allow-methods: GET, DELETE, OPTIONS, POST, PUT
connection: close
```

---

<div class="post-metadata">

**Author:** ![orhantoy](https://avatars.discourse-cdn.com/v4/letter/o/c5a1d2/32.png) [@orhantoy](https://discuss.elastic.co/u/orhantoy)\
**Post date:** [February 9, 2021, 10:17am UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601/9 "2021-02-09T10:17:04Z")

</div>

I'm a bit surprised that you get the error

> An unexpected error occurred: Origin [https://staging.ui.xyz.com](https://staging.ui.xyz.com) is not allowed by Access-Control-Allow-Origin.

when the preflight response includes the header

```auto
access-control-allow-origin: https://staging.ui.xyz.com

```

Do you experience the same error in different browsers?

---

<div class="post-metadata">

**Author:** ![anuragchoudhary01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anuragchoudhary01/32/83611_2.png) [@anuragchoudhary01](https://discuss.elastic.co/u/anuragchoudhary01)\
**Post date:** [February 9, 2021, 4:28pm UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601/10 "2021-02-09T16:28:28Z")

</div>

Yes, I am getting the same error in other browsers as well.  
Safari, Chrome, and Firefox are throwing the same error.

---

<div class="post-metadata">

**Author:** ![orhantoy](https://avatars.discourse-cdn.com/v4/letter/o/c5a1d2/32.png) [@orhantoy](https://discuss.elastic.co/u/orhantoy)\
**Post date:** [February 10, 2021, 10:52am UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601/11 "2021-02-10T10:52:46Z")

</div>

Do you have nginx, Apache, or something else in front of Enterprise Search?

The response headers I get from a Cloud deployment are a bit different from yours:

```auto
access-control-allow-credentials: true
access-control-allow-headers: origin, x-requested-with
access-control-allow-methods: GET, POST
access-control-allow-origin: https://foo.bar.org
access-control-max-age: 7200
cache-control: no-cache
server: Jetty(9.4.30.v20200611)

```

`access-control-allow-methods` are different, and I'm not seeing `allow` in my response.  
I'm wondering if this is a Docker issue 🤔

---

<div class="post-metadata">

**Author:** ![anuragchoudhary01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anuragchoudhary01/32/83611_2.png) [@anuragchoudhary01](https://discuss.elastic.co/u/anuragchoudhary01)\
**Post date:** [February 17, 2021, 12:29pm UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601/12 "2021-02-17T12:29:19Z")

</div>

I have fixed this issue by configuring the CORS setting on HAPROXY.

---

<div class="post-metadata">

**Author:** ![anuragchoudhary01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anuragchoudhary01/32/83611_2.png) [@anuragchoudhary01](https://discuss.elastic.co/u/anuragchoudhary01)\
**Post date:** [September 7, 2021, 12:50pm UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601/13 "2021-09-07T12:50:59Z")

</div>

Hi @orhantoy, I am facing this error now from another URL that is using the same appsearch.

And on HAProxy, I cannot allow multiple URLs.  
Any idea how we can resolve this CORS issue ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:23am UTC](https://discuss.elastic.co/t/cors-error-while-using-the-elastic-enterprise-search/263601/14 "2022-11-04T08:23:38Z")

</div>


