# Upgrading to v7 - CORS issue

**URL:** <https://community.forestadmin.com/t/upgrading-to-v7-cors-issue/2109>\
**Category:** Help me!\
**Created:** [March 16, 2021, 10:02am UTC](https://community.forestadmin.com/t/upgrading-to-v7-cors-issue/2109 "2021-03-16T10:02:12Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bojan\_Antonijevic](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/bojan_antonijevic/32/205_2.png) [@Bojan\_Antonijevic](https://community.forestadmin.com/u/Bojan_Antonijevic)\
**Post date:** [March 16, 2021, 10:02am UTC](https://community.forestadmin.com/t/upgrading-to-v7-cors-issue/2109/1 "2021-03-16T10:02:12Z")

</div>

This is a template you can use to report issues. You can also drag images, videos and include `Preformatted text`

## Expected behavior

Pass the cors request and see the data.

## Actual behavior

`...callback?code=...` request failed due to cors issue and next message appearing on popup:  
Please verify that your admin backend is correctly configured and running.

## Failure Logs

 ![Screenshot 2021-03-16 at 10.18.27](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/f/fcc22d7df16ac357d4bb4c21acb47a5863a176ea.jpeg)  
 ![Shared with CloudApp](https://europe1.discourse-cdn.com/flex013/uploads/forest/optimized/2X/f/fec53a920b463b6a3525643b1189fafc6a694d8f_2_690x77.png)

## Context

Followed by instructions from here [Upgrade to v7 - Documentation](https://docs.forestadmin.com/documentation/how-tos/maintain/upgrade-notes-sql-mongodb/upgrade-to-v7#easier-authentication). We used curl as described to get FOREST\_CLIENT\_ID and set it in .env all together with APPLICATION\_URL. Also changed app.js same as on documentation.

```javascript
curl -H "Content-Type: application/json" \
     -H "Authorization: Bearer FOREST_ENV_SECRET" \
     -X POST \
     -d '{"token_endpoint_auth_method": "none", "redirect_uris": ["APPLICATION_URL/forest/authentication/callback"]}' \
     https://api.forestadmin.com/oidc/reg

```

On the local, everything was working fine. So we want to deploy it to prod env.

Prod has different APPLICATION\_URL and FOREST\_ENV\_SECRET.  
First issue was with `/forest/authentication`. So what we did to fix authentication is:

1. We used CURL to get a new FORECT\_CLIENT\_ID for the prod env and set new values in .env for prod. Authentication is passed !!!

Now we have an **issue** with a cors policy, **but only on prod environments**.  
We tried to solve it by adding a domain to allowedOrigins:

```javascript
let allowedOrigins = [
  /\.forestadmin\.com$/,
  /localhost:\d{4}$/,
  /forestadmin-ENV\.DOMAIN\.io$/,
  /\.forestadmin-ENV\.DOMAIN\.io$/,
];

```

Can you help us with this. Are we in a good direction and what is missing to solve the cors policy issue?

- Package Version: forest-express-sequelize@7.1.0
- Express Version: express@4.16.3
- Sequelize Version: sequelize@5.22.2
- Database Dialect: mysql
- Project Name: TymeshiftFA

---

<div class="post-metadata">

**Author:** ![GuillaumeGautreau](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/guillaumegautreau/32/557_2.png) [@GuillaumeGautreau](https://community.forestadmin.com/u/GuillaumeGautreau)\
**Post date:** [March 16, 2021, 10:09am UTC](https://community.forestadmin.com/t/upgrading-to-v7-cors-issue/2109/2 "2021-03-16T10:09:51Z")

</div>

Hello @Bojan_Antonijevic,

Can you check the headers that are sent in the `OPTIONS` request, to see which `Origin` is sent?

Can you check that the origin `'null'` is allowed for the routes under `/forest/authentication`? This origin is sent by browsers after a redirection, and it’s the case at the end of an authentication request.

---

<div class="post-metadata">

**Author:** ![Bojan\_Antonijevic](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/bojan_antonijevic/32/205_2.png) [@Bojan\_Antonijevic](https://community.forestadmin.com/u/Bojan_Antonijevic)\
**Post date:** [March 16, 2021, 11:57am UTC](https://community.forestadmin.com/t/upgrading-to-v7-cors-issue/2109/3 "2021-03-16T11:57:41Z")

</div>

Hey @GuillaumeGautreau,

About headers on issued request we could see only this:  
[![](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/f/fcc22d7df16ac357d4bb4c21acb47a5863a176ea.jpeg) ](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/f/fcc22d7df16ac357d4bb4c21acb47a5863a176ea.jpeg)

But from some previous request we have:  
 ![Shared with CloudApp](https://europe1.discourse-cdn.com/flex013/uploads/forest/optimized/2X/0/0b26b6e0f018ec1a58e63444c3a936d7fd63ff31_2_560x499.png)

null should be allowed by this?

```javascript
app.use('/forest/authentication', cors({
  ...corsConfig,
  // The null origin is sent by browsers for redirected AJAX calls
  // we need to support this in authentication routes because OIDC
  // redirects to the callback route
  origin: corsConfig.origin.concat('null'),
}));

```

---

<div class="post-metadata">

**Author:** ![GuillaumeGautreau](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/guillaumegautreau/32/557_2.png) [@GuillaumeGautreau](https://community.forestadmin.com/u/GuillaumeGautreau)\
**Post date:** [March 16, 2021, 2:51pm UTC](https://community.forestadmin.com/t/upgrading-to-v7-cors-issue/2109/4 "2021-03-16T14:51:05Z")

</div>

Hello @Bojan_Antonijevic,

Before this request that is failing, you should have a request on the same URI, but with the verb `OPTIONS`. Both headers from the request and the response are important here to be able to identify your issue.

For what I can see, you are showing me headers of the `GET` request, that is blocked by the browser because of the `OPTIONS` request.

Maybe you filtered your network tab to only show `xhr` requests. In this case you cannot see the `OPTIONS` request that is sent just before. Just click on “All” in the network tab to display all requests.

---

<div class="post-metadata">

**Author:** ![Bojan\_Antonijevic](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/bojan_antonijevic/32/205_2.png) [@Bojan\_Antonijevic](https://community.forestadmin.com/u/Bojan_Antonijevic)\
**Post date:** [March 16, 2021, 4:08pm UTC](https://community.forestadmin.com/t/upgrading-to-v7-cors-issue/2109/5 "2021-03-16T16:08:27Z")

</div>

Thanks @GuillaumeGautreau,

Is this one correct?

 ![Screenshot 2021-03-16 at 17.07.02](https://europe1.discourse-cdn.com/flex013/uploads/forest/original/2X/4/4cc6c697819c8839781205955293fa474691b07d.png)

---

<div class="post-metadata">

**Author:** ![GuillaumeGautreau](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/guillaumegautreau/32/557_2.png) [@GuillaumeGautreau](https://community.forestadmin.com/u/GuillaumeGautreau)\
**Post date:** [March 17, 2021, 7:21am UTC](https://community.forestadmin.com/t/upgrading-to-v7-cors-issue/2109/6 "2021-03-17T07:21:53Z")

</div>

Hello @Bojan_Antonijevic,

Thanks for your answer. Yes, this is this request.

As you can see, the requested `Origin` is `null` and the server responds with an authorized origin (`Access-Control-Allow-Origin`) of `https://app.forestadmin.com` which does not match the requested one. Ending up to an error on your browser.

So there is definitively a problem with the code that is supposed to handle cors requests with your agent.

Can you copy/paste all the code that is supposed to handle cors on your agent? Can you check that there is nowhere else some code that handles cors?

Can you also copy/paste the version of `cors` used by your agent?

Thanks

---

<div class="post-metadata">

**Author:** ![Bojan\_Antonijevic](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/bojan_antonijevic/32/205_2.png) [@Bojan\_Antonijevic](https://community.forestadmin.com/u/Bojan_Antonijevic)\
**Post date:** [March 17, 2021, 10:18am UTC](https://community.forestadmin.com/t/upgrading-to-v7-cors-issue/2109/7 "2021-03-17T10:18:21Z")

</div>

Hey @GuillaumeGautreau,

Thank you for your help. The issue was on our side. We change cors in our nginx, which solve the problem.

Appreciate your help.

---

<div class="post-metadata">

**Author:** ![GuillaumeGautreau](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/guillaumegautreau/32/557_2.png) [@GuillaumeGautreau](https://community.forestadmin.com/u/GuillaumeGautreau)\
**Post date:** [March 17, 2021, 10:20am UTC](https://community.forestadmin.com/t/upgrading-to-v7-cors-issue/2109/8 "2021-03-17T10:20:04Z")

</div>

Thanks for the update @Bojan_Antonijevic.

It’s great that you found the solution!
