# Access-control-cross-origin /cors problems

**URL:** <https://forums.suse.com/t/access-control-cross-origin-cors-problems/3124>\
**Category:** Rancher 1.x\
**Created:** [June 15, 2016, 2:04pm UTC](https://forums.suse.com/t/access-control-cross-origin-cors-problems/3124 "2016-06-15T14:04:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jmls](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/jmls/32/1419_2.png) [@jmls](https://forums.suse.com/u/jmls)\
**Post date:** [June 15, 2016, 2:04pm UTC](https://forums.suse.com/t/access-control-cross-origin-cors-problems/3124/1 "2016-06-15T14:04:14Z")

</div>

I’m trying to use the angular $http service to gather some data from the rancher api. However, if I use $http.get() I get the following errors:

```
XMLHttpRequest cannot load https://<rancherIP>/v1-catalog/templates. Response to preflight request doesn't pass access control check: No 'Access-Control-Allow-Origin' header is present on the requested resource. Origin 'https://myAppIP' is therefore not allowed access. The response had HTTP status code 401.

```

So, I tried to use $http.jsonp() - but that comes back with an error of “ **_SyntaxError: Unexpected token \<_** ” because the actual response is not json but …

```
<!DOCTYPE html>
<!-- If you are reading this, there is a good chance you would prefer sending an
"Accept: application/json" header and receiving actual JSON responses. -->
<link rel="stylesheet" type="text/css" href="https://releases.rancher.com/api-ui/1.0.4/ui.min.css" />
<script src="https://releases.rancher.com/api-ui/1.0.4/ui.min.js"></script>
<script> [snip]

```

unfortunately, jsonp does not allow you to add your own headers … so it’s a catch-22. Can’t use .get (but can add header), can use jsonp (but can’t get data)

Is there an option / parameter on the url to specify json as the response, rather than a header option ?

Or is there an option on the rancher server software to enable cors ?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [July 5, 2016, 10:28pm UTC](https://forums.suse.com/t/access-control-cross-origin-cors-problems/3124/2 "2016-07-05T22:28:49Z")

</div>

There is not; an option to set it in [cattle](https://github.com/rancher/cattle) would be ok but it is a generally-bad-idea™ to just add `Access-Control-Allow-Origin: *` by default.

A proxy server to pass requests for [yourdomain.com/v1](http://yourdomain.com/v1) to rancherip/v1 (and a few other paths…) is fairly straightforward and avoids CORS altogether. Here’s the one we use for UI dev: [https://github.com/rancher/ui/blob/master/server/proxies/api.js](https://github.com/rancher/ui/blob/master/server/proxies/api.js)

---

<div class="post-metadata">

**Author:** ![leolly](https://avatars.discourse-cdn.com/v4/letter/l/ba9def/32.png) [@leolly](https://forums.suse.com/u/leolly)\
**Post date:** [August 29, 2016, 9:42am UTC](https://forums.suse.com/t/access-control-cross-origin-cors-problems/3124/3 "2016-08-29T09:42:30Z")

</div>

Hi Vincent, I also encountered this problem, for testing, how to set the option in cattle for enable Access-Control-Allow-Origin: \* by default? Thanks.

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [August 29, 2016, 3:42pm UTC](https://forums.suse.com/t/access-control-cross-origin-cors-problems/3124/4 "2016-08-29T15:42:56Z")

</div>

As I said above there is no option for that.
