# Access-Control-Allow-Origin

**URL:** <https://discourse.nodered.org/t/access-control-allow-origin/32984>\
**Category:** General\
**Created:** [17 September 2020 07:09 UTC](https://discourse.nodered.org/t/access-control-allow-origin/32984 "2020-09-17T07:09:16Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Devbrat](https://avatars.discourse-cdn.com/v4/letter/d/a183cd/32.png) [@Devbrat](https://discourse.nodered.org/u/Devbrat)\
**Post date:** [17 September 2020 07:09 UTC](https://discourse.nodered.org/t/access-control-allow-origin/32984/1 "2020-09-17T07:09:16Z")

</div>

I have added below code in RED.js to enables header for Node-RED. But Access-Control-Allow-Origin header is not coming as [http://google.com/](http://google.com/) . its coming as \*.  
Other headers are reflecting in node-red.

```auto
app.use(function(req, res, next) {
  res.setHeader("Access-Control-Allow-Origin", "http://google.com/");
  res.setHeader('Access-Control-Allow-Methods', 'GET,PUT,POST,DELETE,OPTIONS');
  res.setHeader('Access-Control-Allow-Headers', 'Content-Type, Authorization, Content-Length, X-Requested-With');
  res.setHeader("Content-Security-Policy","frame-ancestors 'none'");        
  res.setHeader("X-Frame-Options", "DENY");
  res.setHeader("X-XSS-Protection", "1; mode=block")
  res.setHeader("Strict-Transport-Security", "max-age=31536000")
  next();
});

```

I want to implement this in node-red level.

Can you tell me how can whitelist some domain in node-red?  
Can I put node-red headers from settings.js as well?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [17 September 2020 10:43 UTC](https://discourse.nodered.org/t/access-control-allow-origin/32984/2 "2020-09-17T10:43:42Z")

</div>

You seem to be amending the core of Node-RED to make it possible to access Node-RED endpoints from an unsecured google location.

This strikes me as unwise on several levels.

Firstly that I doubt that Nick will want this in the core code. Certainly I wouldn't be happy to see it. Additionally, I'm not sure that it is even necessary to put it there but we don't have enough information about what you are trying to do to be able to help.

Secondly, the purpose of those headers is to enable secure connections between domains and so trying to include a non-TLS connected domain is probably not wise. If I remember correctly, I'm not even sure that you _can_ do anything other than "\*" for a non-TLS connection.

> [@Devbrat](#):
>
> Can you tell me how can whitelist some domain in node-red?

Not unless you can explain more about what you are trying to achieve and why you can't do it at the flow level rather than having to hack the core.

---

<div class="post-metadata">

**Author:** ![Devbrat](https://avatars.discourse-cdn.com/v4/letter/d/a183cd/32.png) [@Devbrat](https://discourse.nodered.org/u/Devbrat)\
**Post date:** [23 September 2020 11:51 UTC](https://discourse.nodered.org/t/access-control-allow-origin/32984/3 "2020-09-23T11:51:46Z")

</div>

I want to Configure CORS in Node-RED.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [23 September 2020 12:15 UTC](https://discourse.nodered.org/t/access-control-allow-origin/32984/4 "2020-09-23T12:15:36Z")

</div>

> **[Startpage.com Search results](https://www.startpage.com/do/dsearch?query=node-red%2Bcors&cat=web&pl=opensearch&language=english_uk)**

---

<div class="post-metadata">

**Author:** ![Devbrat](https://avatars.discourse-cdn.com/v4/letter/d/a183cd/32.png) [@Devbrat](https://discourse.nodered.org/u/Devbrat)\
**Post date:** [28 September 2020 09:27 UTC](https://discourse.nodered.org/t/access-control-allow-origin/32984/5 "2020-09-28T09:27:09Z")

</div>

@knolleary Any suggestions on this?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [28 September 2020 09:28 UTC](https://discourse.nodered.org/t/access-control-allow-origin/32984/6 "2020-09-28T09:28:18Z")

</div>

What exactly are you trying to enable CORS on? The editor as a whole or your HTTP In nodes?

---

<div class="post-metadata">

**Author:** ![Devbrat](https://avatars.discourse-cdn.com/v4/letter/d/a183cd/32.png) [@Devbrat](https://discourse.nodered.org/u/Devbrat)\
**Post date:** [28 September 2020 09:56 UTC](https://discourse.nodered.org/t/access-control-allow-origin/32984/7 "2020-09-28T09:56:54Z")

</div>

I am trying to enable for editor as whole. Actually I want to disable all communication except [mydomain.com](http://mydomain.com) from node-red.  
Basically I am trying to whitelist only my domain (One or More)

```auto
app.use(function(req, res, next) {
  res.setHeader("Access-Control-Allow-Origin", "https://mydomain.com/");
  res.setHeader('Access-Control-Allow-Methods', 'GET,PUT,POST,DELETE,OPTIONS');
  res.setHeader('Access-Control-Allow-Headers', 'Content-Type, Authorization, Content-Length, X-Requested-With');
  res.setHeader("Content-Security-Policy","frame-ancestors 'none'");        
  res.setHeader("X-Frame-Options", "DENY");
  res.setHeader("X-XSS-Protection", "1; mode=block")
  res.setHeader("Strict-Transport-Security", "max-age=31536000")
  next();
});

```

I have put above code in red.js, but I am not getting first header "Access-Control-Allow-Origin" to "[https://mydomain.com/](https://mydomain.com/)". Its coming as \*.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [28 September 2020 10:12 UTC](https://discourse.nodered.org/t/access-control-allow-origin/32984/8 "2020-09-28T10:12:19Z")

</div>

You shouldn't need to edit `red.js` - we added `httpAdminMiddleware` in the last release which would allow you to do this via your settings file.

Regardless, it looks like something is overwriting the header somewhere else in the stack. You'd need to trace it through to see what's doing that

---

<div class="post-metadata">

**Author:** ![Devbrat](https://avatars.discourse-cdn.com/v4/letter/d/a183cd/32.png) [@Devbrat](https://discourse.nodered.org/u/Devbrat)\
**Post date:** [28 September 2020 10:14 UTC](https://discourse.nodered.org/t/access-control-allow-origin/32984/9 "2020-09-28T10:14:37Z")

</div>

Okay Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [27 November 2020 10:14 UTC](https://discourse.nodered.org/t/access-control-allow-origin/32984/10 "2020-11-27T10:14:53Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
