# httpStatic files do not seem to use httpNodeCors settings?

**URL:** <https://discourse.nodered.org/t/httpstatic-files-do-not-seem-to-use-httpnodecors-settings/88643>\
**Category:** General\
**Created:** [12 June 2024 17:10 UTC](https://discourse.nodered.org/t/httpstatic-files-do-not-seem-to-use-httpnodecors-settings/88643 "2024-06-12T17:10:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shrickus](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/shrickus/32/517_2.png) [@shrickus](https://discourse.nodered.org/u/shrickus)\
**Post date:** [12 June 2024 17:10 UTC](https://discourse.nodered.org/t/httpstatic-files-do-not-seem-to-use-httpnodecors-settings/88643/1 "2024-06-12T17:10:05Z")

</div>

I have the latest version of node-red v3.x set up with these settings:

```
httpAdminRoot: "/admin",
httpNodeRoot: "/red",
httpStatic: "/opt/nodered/static",

```

and I am able to retrieve the static files using my browser. However, when I try to pull those same urls into [observablehq.com](http://observablehq.com) as data, I am getting CORS errors....

So I added this setting in hopes it would apply to my static file urls:

```
httpNodeCors: {
    origin: "*",
    methods: "GET"
}

```

which does not help, since the static urls are not being handled via `http in` endpoints, I guess, which kinda makes sense. So is there built-in way to disable CORS for static files? Or does this require custom middleware???

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [12 June 2024 19:46 UTC](https://discourse.nodered.org/t/httpstatic-files-do-not-seem-to-use-httpnodecors-settings/88643/2 "2024-06-12T19:46:12Z")

</div>

Please raise an issue - it would make sense for that setting to get applied to httpStatic.

---

<div class="post-metadata">

**Author:** ![shrickus](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/shrickus/32/517_2.png) [@shrickus](https://discourse.nodered.org/u/shrickus)\
**Post date:** [12 June 2024 20:46 UTC](https://discourse.nodered.org/t/httpstatic-files-do-not-seem-to-use-httpnodecors-settings/88643/3 "2024-06-12T20:46:53Z")

</div>

Ok, well that answers that question -- thanks Nick.  
Although now I'm wondering if static routes will need their own configuration, to support public access that is not as strict as http node routes. 🤔

Issue raised... [4759](https://github.com/node-red/node-red/issues/4759)

---

<div class="post-metadata">

**Author:** ![shrickus](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/shrickus/32/517_2.png) [@shrickus](https://discourse.nodered.org/u/shrickus)\
**Post date:** [27 June 2024 20:47 UTC](https://discourse.nodered.org/t/httpstatic-files-do-not-seem-to-use-httpnodecors-settings/88643/4 "2024-06-27T20:47:05Z")

</div>

Looks like this feature has been added to v4.x -- many thanks, Nick!

> <https://github.com/node-red/node-red/pull/4761>
>
> Closes #4759 
> 
> Adds \`httpStaticCors\` to allow cors configuration to be applied… to the \`httpStatic\` routes.
> 
> If \`httpStatic\` is provided as an array of configurations, they can each contain their own \`cors\` property, to allow for per-route configurations.
