# Can't Send HTTP Webhook Requests (CORS Config)

**URL:** <https://community.forestadmin.com/t/cant-send-http-webhook-requests-cors-config/197>\
**Category:** Help me!\
**Created:** [May 15, 2020, 5:20pm UTC](https://community.forestadmin.com/t/cant-send-http-webhook-requests-cors-config/197 "2020-05-15T17:20:50Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/matt/32/141_2.png) [@Matt](https://community.forestadmin.com/u/Matt)\
**Post date:** [May 15, 2020, 5:20pm UTC](https://community.forestadmin.com/t/cant-send-http-webhook-requests-cors-config/197/1 "2020-05-15T17:20:50Z")

</div>

**Expected behavior**

I am looking to be able to successfully send HTTP requests out of forest, and want to understand how to properly set up my Cors config.

**Actual behavior**

Every time I try to send a request I get the following error:

“Access to XMLHttpRequest at ‘_request URL’_ from origin ‘[http://app.forestadmin.com](http://app.forestadmin.com/)’ has been blocked by CORS policy: Response to preflight request doesn’t pass access control check: The value of the ‘Access-Control-Allow-Origin’ header in the response must not be the wildcard ‘\*’ when the request’s credentials mode is ‘include’. The credentials mode of requests initiated by the XMLHttpRequest is controlled by the withCredentials attribute.”

How do I properly setup my cors config if I’m not using rails? And what url do I need to provide? [http://app.forestadmin.com/](http://app.forestadmin.com/) , my url on heroku if I’m using that, or my local server if I’m using development?

Thanks in advance!

**Context**

Please provide any relevant information about your setup.

- Package Version: 0.0.1
- Express Version: 4.16.3
- Sequelize Version: 5.15.1
- Database Dialect: MySQL2
- Database Version: 1.7.0

---

<div class="post-metadata">

**Author:** ![anon36130554](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@anon36130554](https://community.forestadmin.com/u/anon36130554)\
**Post date:** [May 18, 2020, 9:30am UTC](https://community.forestadmin.com/t/cant-send-http-webhook-requests-cors-config/197/2 "2020-05-18T09:30:25Z")

</div>

Hello @Matt 👋

Welcome to our community 🎊

If I’ve understood correctly, your are the using the feature presented [here](https://docs.forestadmin.com/woodshop/how-tos/impersonate-a-user) (making http calls from the Forest UI to other remote instance than your generated project for example)

To allow your browser ([app.forestadmin.com](http://app.forestadmin.com)) to call either your local instance or your instance in Heroku, you need to add the ForestAdmin domain to your CORS configuration (either on your local instance or on your Heroku remote instance).

If I’m not mistaken, you are currently using the `*` as value for the _`Access-Control-Allow-Origin`_ header, which is not authorised in this case (we allow to pass any authentication data that your server might need, if any, such as cookies and so on, which prevents wildcard from being accepted).

Can you try to add _`https://app.forestadmin.com`_ to your CORS configuration please ?

Keep me in touch 🙌

Steve.

---

<div class="post-metadata">

**Author:** ![Matt](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/matt/32/141_2.png) [@Matt](https://community.forestadmin.com/u/Matt)\
**Post date:** [May 18, 2020, 3:05pm UTC](https://community.forestadmin.com/t/cant-send-http-webhook-requests-cors-config/197/3 "2020-05-18T15:05:26Z")

</div>

Hey Steve!

Sounds good. How do I add [https://app.forestadmin.com](https://app.forestadmin.com) to my CORS configuration (where is that?) to both my development/local environment and my heroku/production environment?

---

<div class="post-metadata">

**Author:** ![anon36130554](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@anon36130554](https://community.forestadmin.com/u/anon36130554)\
**Post date:** [May 18, 2020, 3:18pm UTC](https://community.forestadmin.com/t/cant-send-http-webhook-requests-cors-config/197/4 "2020-05-18T15:18:29Z")

</div>

> [@Matt](#):
>
> Sounds good. How do I add [https://app.forestadmin.com](https://app.forestadmin.com) to my CORS configuration (where is that?) to both my development/local environment and my heroku/production environment?

This is easily done :

You should have an `.env` file on both of your environment. In this file, you should see a `CORS_ORIGINS` variable. You can set it to `https://app.forestadmin.com` and you should be ready to go 💪

Keep me in touch 🙌

Steve.

---

<div class="post-metadata">

**Author:** ![Matt](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/matt/32/141_2.png) [@Matt](https://community.forestadmin.com/u/Matt)\
**Post date:** [May 18, 2020, 3:29pm UTC](https://community.forestadmin.com/t/cant-send-http-webhook-requests-cors-config/197/5 "2020-05-18T15:29:49Z")

</div>

Gotcha. I added the code to the .env file as follows:

CORS\_ORIGINS=https://app.forestadmin.com

But am still getting the error on development. Should my setup have two separate .env files for development and production environments?

---

<div class="post-metadata">

**Author:** ![anon36130554](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@anon36130554](https://community.forestadmin.com/u/anon36130554)\
**Post date:** [May 18, 2020, 3:55pm UTC](https://community.forestadmin.com/t/cant-send-http-webhook-requests-cors-config/197/6 "2020-05-18T15:55:36Z")

</div>

> [@Matt](#):
>
> But am still getting the error. Is there something different that I need to do for a local/development environment or should it be working there as well?

So you confirm that for the remote instance it is working, expect for the local one?

If this is the case, the issue might have changed, and the new issue might complain about sending cookie using non https protocol (as while developing, you don’t use ssl certificates).

Can you confirm? Or at least pasting me again the new error message please?

Steve.

---

<div class="post-metadata">

**Author:** ![Matt](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/matt/32/141_2.png) [@Matt](https://community.forestadmin.com/u/Matt)\
**Post date:** [May 18, 2020, 4:09pm UTC](https://community.forestadmin.com/t/cant-send-http-webhook-requests-cors-config/197/7 "2020-05-18T16:09:00Z")

</div>

It looks like I’m still getting the error in both local and remote environments. I entered in the variable CORS\_ORIGINS to equal [https://app.forestadmin.com](https://app.forestadmin.com)

The error says:

“Access to XMLHttpRequest at ‘webhook URL’ from origin ‘[https://app.forestadmin.com](https://app.forestadmin.com)’ has been blocked by CORS policy: Response to preflight request doesn’t pass access control check: The value of the ‘Access-Control-Allow-Origin’ header in the response must not be the wildcard ‘\*’ when the request’s credentials mode is ‘include’. The credentials mode of requests initiated by the XMLHttpRequest is controlled by the withCredentials attribute.”

Still working on seeing if it’s something with my env file.

---

<div class="post-metadata">

**Author:** ![anon36130554](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@anon36130554](https://community.forestadmin.com/u/anon36130554)\
**Post date:** [May 18, 2020, 4:16pm UTC](https://community.forestadmin.com/t/cant-send-http-webhook-requests-cors-config/197/8 "2020-05-18T16:16:20Z")

</div>

It looks like the changes have not been taken into account.

Can you confirm you restarted your servers after the changes?

---

<div class="post-metadata">

**Author:** ![Matt](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/matt/32/141_2.png) [@Matt](https://community.forestadmin.com/u/Matt)\
**Post date:** [May 18, 2020, 4:21pm UTC](https://community.forestadmin.com/t/cant-send-http-webhook-requests-cors-config/197/9 "2020-05-18T16:21:15Z")

</div>

I have restarted my local server and deployed a test to my remote server and am currently still getting the error still. Working on my end to make sure that I’m not missing anything.

---

<div class="post-metadata">

**Author:** ![Matt](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/matt/32/141_2.png) [@Matt](https://community.forestadmin.com/u/Matt)\
**Post date:** [May 18, 2020, 5:03pm UTC](https://community.forestadmin.com/t/cant-send-http-webhook-requests-cors-config/197/10 "2020-05-18T17:03:27Z")

</div>

Got it working! Looks like it was the way the request syntax was structured. Thank you so much for your help! This opened up a lot of doors for us to utilize Forest even more!
