# CORS issue in Elasticsearch v2.3.3

**URL:** <https://discuss.elastic.co/t/cors-issue-in-elasticsearch-v2-3-3/55518>\
**Category:** Elasticsearch\
**Created:** [July 14, 2016, 12:50pm UTC](https://discuss.elastic.co/t/cors-issue-in-elasticsearch-v2-3-3/55518 "2016-07-14T12:50:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sheilj](https://avatars.discourse-cdn.com/v4/letter/s/aca169/32.png) [@sheilj](https://discuss.elastic.co/u/sheilj)\
**Post date:** [July 14, 2016, 12:50pm UTC](https://discuss.elastic.co/t/cors-issue-in-elasticsearch-v2-3-3/55518/1 "2016-07-14T12:50:09Z")

</div>

Hi, we are calling the elasticsearch (2.3.3.) from javascript code, using http methods. What in the headers do we need to set in the http request to get rid of the following error:  
Request header content-type was not present in the Access-Control-Allow-Headers list.

Any help is appreciated, struggling with this issue since some time now.

---

<div class="post-metadata">

**Author:** ![abeyad](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@abeyad](https://discuss.elastic.co/u/abeyad)\
**Post date:** [July 14, 2016, 1:29pm UTC](https://discuss.elastic.co/t/cors-issue-in-elasticsearch-v2-3-3/55518/2 "2016-07-14T13:29:08Z")

</div>

What value(s) do you have set for `http.cors.allow-headers` in your `elasticsearch.yml` file? And what headers are sending in your CORS request?

---

<div class="post-metadata">

**Author:** ![sheilj](https://avatars.discourse-cdn.com/v4/letter/s/aca169/32.png) [@sheilj](https://discuss.elastic.co/u/sheilj)\
**Post date:** [July 15, 2016, 10:48am UTC](https://discuss.elastic.co/t/cors-issue-in-elasticsearch-v2-3-3/55518/3 "2016-07-15T10:48:19Z")

</div>

I had added the following in the .yml file:  
http.cors.enabled : true  
http.cors.allow-origin : "\*"

The issue got resolved when we set the 'Content-Type': 'text/plain', earlier it was set to 'application/json' because of which it was not passing the preflight check i guess. Let me know if my understanding is correct. Thanks.

---

<div class="post-metadata">

**Author:** ![abeyad](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@abeyad](https://discuss.elastic.co/u/abeyad)\
**Post date:** [July 15, 2016, 2:13pm UTC](https://discuss.elastic.co/t/cors-issue-in-elasticsearch-v2-3-3/55518/4 "2016-07-15T14:13:41Z")

</div>

Correct, `application/json` is not an allowed `Content-Type` for CORS requests, see: [http://www.w3.org/TR/cors/#simple-header](http://www.w3.org/TR/cors/#simple-header) for the allowed `Content-Type` values for CORS

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:35pm UTC](https://discuss.elastic.co/t/cors-issue-in-elasticsearch-v2-3-3/55518/5 "2017-07-05T22:35:08Z")

</div>


