# CORS Error while setting up to production

**URL:** <https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788>\
**Category:** Help me!\
**Tags:** setup\
**Created:** [June 24, 2021, 1:21pm UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788 "2021-06-24T13:21:58Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anupam\_Rana](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/anupam_rana/32/2523_2.png) [@Anupam\_Rana](https://community.forestadmin.com/u/Anupam_Rana)\
**Post date:** [June 24, 2021, 1:21pm UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/1 "2021-06-24T13:21:58Z")

</div>

## Expected behavior

The app works perfectly fine in the development environment. After updating the .env file and deploying it on the server the app should work fine in the production environment as well.

## Actual behavior

But I receive the following CORS error when I try to open the app in the production environment.

 ![Screenshot 2021-06-24 at 6.32.06 PM](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/e/e52427591b0d193660a047767fdfb16fff804950.png)

Following is the .env file in production

```javascript
APPLICATION_URL= *_application URL_*
APPLICATION_PORT=5000
PORT=5000
NODE_ENV=Production
CORS_ORIGINS=
DATABASE_URL= *_Mongo DB URL_*
DATABASE_SSL=true
DATABASE_REJECT_UNAUTHORIZED=false
FOREST_ENV_SECRET= *_FOREST_ENV_SECRET_*
FOREST_AUTH_SECRET=*_FOREST_AUTH_SECRET_*

```

Following is the code used for the CORS policies:

```javascript
let allowedOrigins = [/\.forestadmin\.com$/, /localhost:\d{4}$/]

if (process.env.CORS_ORIGINS) {
  allowedOrigins = allowedOrigins.concat(process.env.CORS_ORIGINS.split(','));
}
const corsConfig = {
  origin: allowedOrigins,
  maxAge: 86400, // NOTICE: 1 day
  credentials: true,
};
app.use('/forest/authentication', cors({
  ...corsConfig,
  origin: corsConfig.origin.concat('null')
}));
app.use(cors(corsConfig));

```

I am running the node server in an EC2 instance on port 5000 and redirecting is done using NGINX.

It would be really great if the community could me out with resolving this issue.

---

<div class="post-metadata">

**Author:** ![anon16419211](https://avatars.discourse-cdn.com/v4/letter/a/7cd45c/32.png) [@anon16419211](https://community.forestadmin.com/u/anon16419211)\
**Post date:** [June 24, 2021, 2:46pm UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/2 "2021-06-24T14:46:10Z")

</div>

Hello @Anupam_Rana and welcome on our cumunity forum,

Can you please give me your project name? And also, is your EC2 instance allowing forestadmin to share ressources with ?

Kind regards,  
Louis

---

<div class="post-metadata">

**Author:** ![Anupam\_Rana](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/anupam_rana/32/2523_2.png) [@Anupam\_Rana](https://community.forestadmin.com/u/Anupam_Rana)\
**Post date:** [June 25, 2021, 4:44am UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/3 "2021-06-25T04:44:48Z")

</div>

Thanks, lclisson for the quick response. The project name is “mScribe - Stagging”.

**Sorry I didn’t exactly get what you mean by "is your EC2 instance allowing forestadmin to share resources with ?"**

Also, when I make the following curl request on the server:  
`curl -I https://d1435vzflg6dnd.cloudfront.net/forest`

I get the following response:

```javascript
HTTP/2 204
date: Fri, 25 Jun 2021 04:40:46 GMT
server: nginx/1.18.0 (Ubuntu)
x-powered-by: Express
vary: Origin
access-control-allow-credentials: true
x-cache: Miss from cloudfront
via: 1.1 418a67fef069e9fd015a10adc259465a.cloudfront.net (CloudFront)
x-amz-cf-pop: BOM51-C2
x-amz-cf-id: 6NkInADUNtBcstMyTgQh5fuE0_nLvMnbqiKIjpvBAaUsvHUnSUs7yw==

```

And following is the error while trying to app the app in the production environment:

 ![Screenshot 2021-06-25 at 9.58.48 AM](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/3/3e716f7ab43c13935880b9eed804e549af9b61c1.png)

 ![Screenshot 2021-06-25 at 10.14.03 AM](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/8/83aa7f7b562d5cdb89e5ac90360521e85a363fa7.png)

---

<div class="post-metadata">

**Author:** ![anon16419211](https://avatars.discourse-cdn.com/v4/letter/a/7cd45c/32.png) [@anon16419211](https://community.forestadmin.com/u/anon16419211)\
**Post date:** [June 25, 2021, 8:10am UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/4 "2021-06-25T08:10:34Z")

</div>

I was thinking of if you were able to ping your server or not, which you just did successfully.

The CORS issue you’r facing is probably due to a misconfiguration on a header sent with the request. Can you please share to me the request & response header of the failing request? 🙂

---

<div class="post-metadata">

**Author:** ![Anupam\_Rana](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/anupam_rana/32/2523_2.png) [@Anupam\_Rana](https://community.forestadmin.com/u/Anupam_Rana)\
**Post date:** [June 25, 2021, 9:32am UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/5 "2021-06-25T09:32:38Z")

</div>

Following is the request & response header of the failing request:

 ![Screenshot 2021-06-25 at 2.58.21 PM](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/6/603209a59b57856e54d46b4e9a8bd605d1fc5649.png)

 ![Screenshot 2021-06-25 at 2.58.33 PM](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/b/b026671458773c7af6c0d50365a262f6ca6c3a4e.png)

Also following is the error that is being displayed on the console:

 ![Screenshot 2021-06-25 at 3.01.22 PM](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/6/6543975bfebf0ac635e6c66a4780e2eb4a81a3c9.png)

I have also attached the CORS configuration in the above messages.

---

<div class="post-metadata">

**Author:** ![anon16419211](https://avatars.discourse-cdn.com/v4/letter/a/7cd45c/32.png) [@anon16419211](https://community.forestadmin.com/u/anon16419211)\
**Post date:** [June 25, 2021, 1:35pm UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/6 "2021-06-25T13:35:55Z")

</div>

Can you try to set this _corsConfig_ object instead of the one you have in your **app.js** file please and let me know if it helps 🙂

```javascript
const corsConfig = {
  origin: allowedOrigins,
  allowedHeaders: ['Authorization', 'X-Requested-With', 'Content-Type'],
  maxAge: 86400, // NOTICE: 1 day
  credentials: true,
};

```

---

<div class="post-metadata">

**Author:** ![Anupam\_Rana](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/anupam_rana/32/2523_2.png) [@Anupam\_Rana](https://community.forestadmin.com/u/Anupam_Rana)\
**Post date:** [June 25, 2021, 2:13pm UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/7 "2021-06-25T14:13:08Z")

</div>

Thanks lclisson. I have updated the corsConfig which you have shared and the CORS issue has been resolved and the issue is no more reflecting in the console.

But I am seeing a strange thing in the console. I have updated the production link in forestadmin dashboard as well as in the .env file as the production app link. But still, in the console authentication, the API is getting hit on the localhost URL. I guess if we resolve that the app should start working.  
Following is a screenshot for reference:

 ![Screenshot 2021-06-25 at 7.42.23 PM](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/3/3ab3646e28b36cb4e8a12913829ada444bb8b09e.png)

---

<div class="post-metadata">

**Author:** ![anon16419211](https://avatars.discourse-cdn.com/v4/letter/a/7cd45c/32.png) [@anon16419211](https://community.forestadmin.com/u/anon16419211)\
**Post date:** [June 25, 2021, 2:35pm UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/8 "2021-06-25T14:35:31Z")

</div>

What value of APPLICATION\_URL have you defined in .env file ? 🙂

---

<div class="post-metadata">

**Author:** ![Anupam\_Rana](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/anupam_rana/32/2523_2.png) [@Anupam\_Rana](https://community.forestadmin.com/u/Anupam_Rana)\
**Post date:** [June 25, 2021, 3:15pm UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/9 "2021-06-25T15:15:02Z")

</div>

Following is the value defined in .env file:

 ![Screenshot 2021-06-25 at 8.40.24 PM](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/f/f6d15844d6494697b7b8f48249fcd9296f6cbe6e.png)

Also, the following is the value in the forestadmin app:

 ![Screenshot 2021-06-25 at 8.41.04 PM](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/a/ace4554091450f5dc9f8e822b052c32439ce440a.png)

---

<div class="post-metadata">

**Author:** ![anon16419211](https://avatars.discourse-cdn.com/v4/letter/a/7cd45c/32.png) [@anon16419211](https://community.forestadmin.com/u/anon16419211)\
**Post date:** [June 25, 2021, 3:18pm UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/10 "2021-06-25T15:18:00Z")

</div>

What is the network call that is failing & what is the response from it?

Do you have any logs from your server that could help?

---

<div class="post-metadata">

**Author:** ![Anupam\_Rana](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/anupam_rana/32/2523_2.png) [@Anupam\_Rana](https://community.forestadmin.com/u/Anupam_Rana)\
**Post date:** [June 26, 2021, 5:15am UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/11 "2021-06-26T05:15:57Z")

</div>

Following are the logs in the server:

 ![Screenshot 2021-06-25 at 10.54.48 PM](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/a/aac285c5beb7b3745c1c4cfc5982bf8e4dfce5b7.png)

Following is networ call:

 ![Screenshot 2021-06-25 at 10.55.06 PM](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/e/e468dda62bb993c702f01800b6b9a0b6bcf4edf7.png)

And following is the response:  
`{"errors":[{"status":500,"detail":"Invalid response from the authentication server: the state parameter is missing","name":"Error"}]}`

---

<div class="post-metadata">

**Author:** ![anon16419211](https://avatars.discourse-cdn.com/v4/letter/a/7cd45c/32.png) [@anon16419211](https://community.forestadmin.com/u/anon16419211)\
**Post date:** [June 28, 2021, 9:00am UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/12 "2021-06-28T09:00:15Z")

</div>

The format of the request sent to your server is correct and I don’t see any misconfiguration from that point of view. As there was an error in your app.js file before, can you share with me all the content of the file so I can double check everything is all right ?

---

<div class="post-metadata">

**Author:** ![Anupam\_Rana](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/anupam_rana/32/2523_2.png) [@Anupam\_Rana](https://community.forestadmin.com/u/Anupam_Rana)\
**Post date:** [June 28, 2021, 12:19pm UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/13 "2021-06-28T12:19:42Z")

</div>

Sure lclisson. Following is the content of the app.js file:

```javascript
const dotenv = require('dotenv').config();
const express = require('express');
const fs = require('fs');
const fileType = require('file-type');
const multiparty = require('multiparty');
const path = require("path");
var Mongoose = require('mongoose');
const forest = require('forest-express-mongoose');
const DoctorSchema = require('./models/doctorSchema');
const PrescriptionSchema = require('./models/prescriptionSchema');
const cors = require('cors');

Mongoose.Promise = require('bluebird');
Mongoose.connect(process.env.DATABASE_URL, { useNewUrlParser: true, useUnifiedTopology: true });
const connection = Mongoose.connections[0];
console.log("DB Connected", process.env.DATABASE_URL);

const app = express();

var port = process.env.PORT || 5000;
let allowedOrigins = [/\.forestadmin\.com$/, /localhost:\d{4}$/, /\.mscribe\.com$/, 'mscribe.com', 'www.mscribe.com', "https://mscribe.in", "https://www.mscribe.in", "http://www.mscribe.in", "http://mscribe.in"]

if (process.env.CORS_ORIGINS) {
    allowedOrigins = allowedOrigins.concat(process.env.CORS_ORIGINS.split(','));
}

const corsConfig = {
    origin: allowedOrigins,
    maxAge: 86400, // NOTICE: 1 day
    credentials: true,
};

app.use('/forest/authentication', cors({
    ...corsConfig,
    origin: corsConfig.origin.concat('null')
}));

app.use(cors(corsConfig));

app.get('/', (req, res) => {
    res.send("Hi! I am servy and I love to serve API requests - Mscribe Backend - 4");
});

app.listen(port, async () => {
    app.use(
        await forest.init({
            envSecret: process.env.FOREST_ENV_SECRET,
            authSecret: process.env.FOREST_AUTH_SECRET,
            objectMapping: Mongoose,
            connections: { default: connection },
        })
    );
});

console.log('Server up and running...', port);

```

---

<div class="post-metadata">

**Author:** ![anon16419211](https://avatars.discourse-cdn.com/v4/letter/a/7cd45c/32.png) [@anon16419211](https://community.forestadmin.com/u/anon16419211)\
**Post date:** [June 29, 2021, 8:17am UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/14 "2021-06-29T08:17:56Z")

</div>

> [@Anupam\_Rana](#):
>
> mScribe

Looking at the creation date of your project and the lumber version used to generate it, I can see that the generated files are not the ones you are supposed to have and it could explain the authentication issue you are having 🙂

Have you copy/paste some files from a previous project? From what I see the easiest things should be to generate a new project with the latest lumber version which you can installed by running  
`npm install -g lumber-cli@latest -s`

---

<div class="post-metadata">

**Author:** ![louis](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/louis/32/4_2.png) [@louis](https://community.forestadmin.com/u/louis)\
**Post date:** [July 7, 2021, 7:38am UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/15 "2021-07-07T07:38:49Z")

</div>

Hey all,

After investigating, it turned out that CloudFront was causing the issues:

- CloudFront was removing any query parameters from request, preventing the authentication system to perform correctly
- CloudFront was removing any headers preventing users from being correctly identified agent side (and thus 401 errors were always thrown)

@Anupam_Rana I let you add any useful information 🙏

---

<div class="post-metadata">

**Author:** ![Anupam\_Rana](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/anupam_rana/32/2523_2.png) [@Anupam\_Rana](https://community.forestadmin.com/u/Anupam_Rana)\
**Post date:** [July 9, 2021, 4:17am UTC](https://community.forestadmin.com/t/cors-error-while-setting-up-to-production/2788/16 "2021-07-09T04:17:31Z")

</div>

Thanks, team Forestadmin for the quick resolution of the issue.

As mentioned above the project was working in a development environment but was not working in production when deployed on EC2 and sending the requests via CloudFront.

The first issue was that CloudFront in its default setting that removes the query parameters and headers from the request. You need to change the setting to allow all query parameters to be forwarded with the request. For headers, you need to allow origin and authorization headers to be forwarded.
