# Elasticsearch not working with CORS

**URL:** <https://discuss.elastic.co/t/elasticsearch-not-working-with-cors/79152>\
**Category:** Elasticsearch\
**Created:** [March 19, 2017, 12:46am UTC](https://discuss.elastic.co/t/elasticsearch-not-working-with-cors/79152 "2017-03-19T00:46:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ExiaSR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exiasr/32/16479_2.png) [@ExiaSR](https://discuss.elastic.co/u/ExiaSR)\
**Post date:** [March 19, 2017, 12:46am UTC](https://discuss.elastic.co/t/elasticsearch-not-working-with-cors/79152/1 "2017-03-19T00:46:34Z")

</div>

- Elasticsearch 5.2.2

I am using a http client library (axios) with web app to send request to the elasticsearch, however, after the preflight OPTIONS request, nothing happen after it. Thank you.

NOTE: I am able to use any CLI tool like curl to send a request to the elasticsearch, and it works fine.

My config file

```auto
http.cors.enabled: true
http.cors.allow-origin: "*"
http.cors.allow-methods: OPTIONS, HEAD, GET, POST, PUT, DELETE
http.cors.allow-headers: "X-Requested-With,X-Auth-Token,Content-Type, Content-Length"

```

Request header

```auto
OPTIONS http://localhost:9200/xxx/_search
Host: localhost:9200
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:54.0) Gecko/20100101 Firefox/54.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Access-Control-Request-Method: POST
Access-Control-Request-Headers: authorization
Origin: http://localhost:3000
Connection: keep-alive
Cache-Control: max-age=0

```

Respond header

```auto
Access-Control-Allow-Origin: "*"
Access-Control-Allow-Methods: "HEAD,DELETE,POST,GET,OPTIONS,PUT"
Access-Control-Allow-Headers: "X-Requested-With,X-Auth-Token, Content-Length,Content-Type"
Access-Control-Max-Age: "1728000"
Date: "\"Sun, 19 Mar 2017 00:28:32 GMT\""
Content-Length: "0"

```

---

<div class="post-metadata">

**Author:** ![abeyad](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@abeyad](https://discuss.elastic.co/u/abeyad)\
**Post date:** [March 24, 2017, 2:23pm UTC](https://discuss.elastic.co/t/elasticsearch-not-working-with-cors/79152/2 "2017-03-24T14:23:07Z")

</div>

There was a bug where the allow-methods and allow-headers settings could not have spaces in between comma-delimited values: [Allow comma delimited array settings to have a space after each entry by abeyad · Pull Request #22591 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/pull/22591). Its fixed in 5.3. For now, you have to make sure there is no whitespace between your allow-methods and allow-headers values...e.g.

http.cors.allow-methods: OPTIONS,HEAD,GET,POST,PUT,DELETE  
http.cors.allow-headers: X-Requested-With,X-Auth-Token,Content-Type,Content-Length

That could be your problem.

Also, your request contains the request header "authorization" but that's not listed as one of your allow-headers?

> NOTE: I am able to use any CLI tool like curl to send a request to the elasticsearch, and it works fine.

Not sure I follow - you were able to execute requests using a CLI tool but not your client library? In that case, the issue may be within your client library config?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2017, 2:23pm UTC](https://discuss.elastic.co/t/elasticsearch-not-working-with-cors/79152/3 "2017-04-21T14:23:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
