Errors / Blocked by the browser
Response to preflight request doesn't pass access control check
Before sending its real request, the browser asked the other server for permission, and did not get it.
The real request is never sent.
Why it happens
- A request with a JSON body, an
Authorizationheader or a method other than GET/POST makes the browser send anOPTIONSrequest first. - The server does not answer
OPTIONS(404, 405, or a redirect), or answers withoutAccess-Control-Allow-Methods/Access-Control-Allow-Headersfor what the page sends. Access-Control-Allow-Origin: *together with credentials (cookies), which browsers refuse.
How to fix it
- Make the server answer
OPTIONSwith 204 and theAccess-Control-Allow-Origin,-Methodsand-Headersthe real request needs. - With cookies, name the origin exactly and add
Access-Control-Allow-Credentials: true. - Never redirect a preflight: fix the URL (trailing slash,
http→https) instead.
Whose problem it is
Usually the server that answers the request.
Does your site have it?
Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.
Often seen with
- Blocked by CORS policyThe page asked another website for data, and that website did not say this page may read it.