# CORS ERROR on localhost

**URL:** <https://community.forestadmin.com/t/cors-error-on-localhost/6415>\
**Category:** Help me!\
**Tags:** login, cors, locahost\
**Created:** [June 20, 2023, 10:11am UTC](https://community.forestadmin.com/t/cors-error-on-localhost/6415 "2023-06-20T10:11:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![flo-3](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/flo-3/32/6239_2.png) [@flo-3](https://community.forestadmin.com/u/flo-3)\
**Post date:** [June 20, 2023, 10:11am UTC](https://community.forestadmin.com/t/cors-error-on-localhost/6415/1 "2023-06-20T10:11:57Z")

</div>

## Feature(s) impacted

Local Dev Environment Authentication

## Observed behavior

Agent unreachable / Unable to authenticate you from the dashboard  
Works well if I curl the same API: [http://localhost:3000/forest](http://localhost:3000/forest) =\> “message”:“Agent is running”

## Expected behavior

See my data on the dashboard

## Failure Logs

```javascript
CORS error: Access to fetch at 'http://localhost:3000/forest/authentication' 
from origin 'https://app.forestadmin.com' has been blocked by CORS policy: 
Response to preflight request doesnt pass access control check: 
The value of the 'Access-Control-Allow-Origin' header in the response must not be the wildcard '*' when the request's credentials mode is 'include'.

```

## Context

- Environment name: development
- I’m using  
“@forestadmin/agent”: “^1.12.0”,  
“@forestadmin/datasource-mongoose”: “^1.4.0”
- Agent creation:

```javascript
createAgent({
  authSecret: process.env.FOREST_AUTH_SECRET,
  envSecret: process.env.FOREST_ENV_SECRET,
  isProduction: process.env.NODE_ENV === 'production',

})
  // Create your Mongoose datasource
  .addDataSource(createMongooseDataSource(mongoose.connection))
  .mountOnExpress(app)
  .start();

```

- Database type: MongoDB
- Recent changes made on your end if any:  
I added CORS handling on my app.js:

```javascript
const allowedOrigins = ['https://app.forestadmin.com', process.env.FRONT_URL];
app.use((req, res, next) => {
  const origin = req.headers.origin;
  if (allowedOrigins.includes(origin)) {
    res.setHeader('Access-Control-Allow-Origin', origin);
  }
  res.setHeader('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE');
  res.setHeader('Access-Control-Allow-Headers', 'Content-Type, Authorization');
  res.setHeader('Access-Control-Allow-Credentials', 'true');
  next();
});

```

---

<div class="post-metadata">

**Author:** ![anon62739609](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@anon62739609](https://community.forestadmin.com/u/anon62739609)\
**Post date:** [June 20, 2023, 1:19pm UTC](https://community.forestadmin.com/t/cors-error-on-localhost/6415/2 "2023-06-20T13:19:11Z")

</div>

Hi @flo-3,

Looking at the [documentation](https://docs.forestadmin.com/developer-guide-agents-nodejs/getting-started/install/troubleshooting#cross-origin-resource-sharing-cors), you must mount first forest then your CORS middleware

---

<div class="post-metadata">

**Author:** ![flo-3](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/flo-3/32/6239_2.png) [@flo-3](https://community.forestadmin.com/u/flo-3)\
**Post date:** [June 21, 2023, 9:58am UTC](https://community.forestadmin.com/t/cors-error-on-localhost/6415/3 "2023-06-21T09:58:27Z")

</div>

Hello,

I mounted first forest + used the CORS package and it worked!  
Thank you 🙂
