# CORS problem in custom REST endpoint

**URL:** <https://forum.keycloak.org/t/cors-problem-in-custom-rest-endpoint/7437>\
**Category:** Getting advice\
**Created:** [February 17, 2021, 10:54am UTC](https://forum.keycloak.org/t/cors-problem-in-custom-rest-endpoint/7437 "2021-02-17T10:54:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![daryaorel](https://avatars.discourse-cdn.com/v4/letter/d/f475e1/32.png) [@daryaorel](https://forum.keycloak.org/u/daryaorel)\
**Post date:** [February 17, 2021, 10:54am UTC](https://forum.keycloak.org/t/cors-problem-in-custom-rest-endpoint/7437/1 "2021-02-17T10:54:11Z")

</div>

Hello,

For the needs of our project, we’ve created a plugin to implement a custom REST endpoint by using the following documentation: [Server Developer Guide](https://www.keycloak.org/docs/latest/server_development/#_extensions_rest).

By calling this endpoint via a front application, we have a CORS problem: “has been blocked by CORS policy: Response to preflight request doesn’t pass access control check: No ‘Access-Control-Allow-Origin’ header is present on the requested resource.”

However, by using a REST Postman client, we don’t have that problem.

To resolve this issue, we’ve tried to manually add the “Access-Control-Allow-Origin” header in the response using following technics:

1. return Response.ok().entity(data).header(“Access-Control-Allow-Origin”, “\*”).build();

2. return Cors.add(request, Response.ok().entity(data))  
.preflight()  
.allowAllOrigins()  
.allowedMethods(“GET”, “PUT”, “POST”, “DELETE”)  
.auth()  
.build();

3. return Response  
.status(200)  
.header(“Access-Control-Allow-Origin”, “\*”)  
.header(“Access-Control-Allow-Headers”, “origin, content-type, accept, authorization”)  
.header(“Access-Control-Allow-Methods”, “GET, POST, PUT, DELETE, OPTIONS, HEAD”)  
.entity(data)  
.build();

By using a REST Postman client, we’ve observed that some of those technics have allowed us to add the needed header in the response, but the front application still wasn’t working.

To test the theory that we cannot allow all origins, we’ve tried to limit them to the precise ones, which also haven’t given any results.

Adding ‘cors: true’ or ‘“enable-cors”: true’ in keycloak.json of the front application also hasn’t solved this issue.

Could you advise us on the solution to this problem, please?

---

<div class="post-metadata">

**Author:** ![jangaraj](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/jangaraj/32/5175_2.png) [@jangaraj](https://forum.keycloak.org/u/jangaraj)\
**Post date:** [February 17, 2021, 1:26pm UTC](https://forum.keycloak.org/t/cors-problem-in-custom-rest-endpoint/7437/2 "2021-02-17T13:26:17Z")

</div>

See spec: [Access-Control-Allow-Headers - HTTP | MDN](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Access-Control-Allow-Headers)

> In requests with credentials, it is treated as the literal header name " `*` " without special semantics. Note that the [`Authorization`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Authorization) header can’t be wildcarded and always needs to be listed explicitly.

 ![image](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/0/01206d89d22cc87a556229425814c5efb9c36ee7.png)

So are you allowing all origins with wild char or just one origin with literal name `*`? I guess second option is right.

---

<div class="post-metadata">

**Author:** ![daryaorel](https://avatars.discourse-cdn.com/v4/letter/d/f475e1/32.png) [@daryaorel](https://forum.keycloak.org/u/daryaorel)\
**Post date:** [February 17, 2021, 4:35pm UTC](https://forum.keycloak.org/t/cors-problem-in-custom-rest-endpoint/7437/3 "2021-02-17T16:35:21Z")

</div>

We’ve tried to use localhost origin instead of \*, but it hasn’t worked either.

---

<div class="post-metadata">

**Author:** ![jangaraj](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/jangaraj/32/5175_2.png) [@jangaraj](https://forum.keycloak.org/u/jangaraj)\
**Post date:** [February 17, 2021, 5:01pm UTC](https://forum.keycloak.org/t/cors-problem-in-custom-rest-endpoint/7437/4 "2021-02-17T17:01:12Z")

</div>

Doc is your good friend for development: [Origin - HTTP | MDN](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Origin)

> Origin: \<scheme\> “://” \<hostname\> [“:” \<port\>]

`localhost` is definitely not a valid origin. Also some browsers (google: `chrome cors issue localhost`) may ignore it for localhost origin.

---

<div class="post-metadata">

**Author:** ![daryaorel](https://avatars.discourse-cdn.com/v4/letter/d/f475e1/32.png) [@daryaorel](https://forum.keycloak.org/u/daryaorel)\
**Post date:** [March 4, 2021, 10:41am UTC](https://forum.keycloak.org/t/cors-problem-in-custom-rest-endpoint/7437/5 "2021-03-04T10:41:28Z")

</div>

I haven’t used directly `localhost`, I used it as `http://localhost:3000`. But it doesn’t work. I’ve tried other browsers. It doesn’t work either.

---

<div class="post-metadata">

**Author:** ![Najm\_R](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/najm_r/32/3247_2.png) [@Najm\_R](https://forum.keycloak.org/u/Najm_R)\
**Post date:** [May 28, 2021, 6:29pm UTC](https://forum.keycloak.org/t/cors-problem-in-custom-rest-endpoint/7437/6 "2021-05-28T18:29:25Z")

</div>

Hi, i’m facing the same problem here. Have you found a way to configure CORS on a Keycloak custom rest endpoint?

---

<div class="post-metadata">

**Author:** ![ibrabool](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/ibrabool/32/3708_2.png) [@ibrabool](https://forum.keycloak.org/u/ibrabool)\
**Post date:** [August 12, 2021, 11:13am UTC](https://forum.keycloak.org/t/cors-problem-in-custom-rest-endpoint/7437/7 "2021-08-12T11:13:28Z")

</div>

Hi, I’m using keycloak 9.0.2. I’ve tried adding endpoint api as well as adding custom module as described in the keycloak provider examples; when reaching the apis with authentication, both give the same as described above: CORS preflight didn’t succeed. Any luck in thinking this problem through?  
Thanks
