# How to enable CORS

**URL:** <https://forum.serverless.com/t/how-to-enable-cors/13228>\
**Category:** Serverless Framework\
**Tags:** lambda, cloudformation, api-gateway\
**Created:** [November 26, 2020, 6:26pm UTC](https://forum.serverless.com/t/how-to-enable-cors/13228 "2020-11-26T18:26:10Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mithundas79](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/mithundas79/32/4454_2.png) [@mithundas79](https://forum.serverless.com/u/mithundas79)\
**Post date:** [November 26, 2020, 6:26pm UTC](https://forum.serverless.com/t/how-to-enable-cors/13228/1 "2020-11-26T18:26:10Z")

</div>

Hi - I am using the following version of serverless for my lambda project

```auto
Framework Core: 1.78.1
Plugin: 3.7.0
SDK: 2.3.1
Components: 2.34.5

```

I have following in the serverless.yml

```auto
  AdminTokenVerify: 
    handler: src/handlers/Admins/auth.auth
  AdminLogin:
    handler: src/handlers/Admins/auth.login
    memorySize: 3008
    timeout: 15
    events:
      - http:
          path: admins/login
          method: post
          cors: true
  AdminRefreshToken:
    handler: src/handlers/Admins/auth.refreshToken
    memorySize: 3008
    timeout: 15
    events:
      - http:
          path: admins/refresh-token
          method: get
          cors: true
          authorizer: 
            name: AdminTokenVerify
            type: token

```

and in my handler I use

```auto
.then((response) => {
        return {
          statusCode: 200,
          headers: {
            'Access-Control-Allow-Origin': '*', // Required for CORS support to work
            'Access-Control-Allow-Credentials': true // Required for CORS support to work
          },
          body: JSON.stringify({
            isSuccess: true,
            data: {
              token: response.token,
              action: response.action
            },
            message: "Login message"
          }, null, 2)
        };
      })

```

the above example is for the return of the login handler. In the refsh token function return object the headers are the same.  
I get response in POSTMAN but when i try with jquery in browser I get →

> Access to XMLHttpRequest at ‘[https://rmmsyr6o93f.execute-api.eu-central-1.amazonaws.com/dev/admins/login](https://rmmsyr6o93f.execute-api.eu-central-1.amazonaws.com/dev/admins/login)’ from origin ‘null’ has been blocked by CORS policy: No ‘Access-Control-Allow-Origin’ header is present on the requested resource.

My client code is following

```auto
$.ajax
    ({
        dataType: "json",
        method: "post",
        url: url,
        headers: {
            "Content-Type": "application/json"
        },
        data: {email: email, password: password},
        success: function(data) 
        {
            console.log("log response on success");
            console.log(data);
        },
        error: function(err) 
        {
            console.log("log response on error");
            console.log(err);
        }
    });

```

Also I read the below guide

> **[Your CORS and API Gateway survival guide](https://www.serverless.com/blog/cors-api-gateway-survival-guide)**
>
> Get the basics on Cross-Origin Resource Sharing (CORS) and how to avoid problems with your Serverless web APIs on Lambda.

And tried following in my sertverless.yml

```auto
resources:
  Resources:
    GatewayResponseDefault4XX:
      Type: 'AWS::ApiGateway::GatewayResponse'
      Properties:
        ResponseParameters:
          gatewayresponse.header.Access-Control-Allow-Origin: "'*'"
          gatewayresponse.header.Access-Control-Allow-Headers: "'*'"
        ResponseType: DEFAULT_4XX
        RestApiId:
          Ref: 'ApiGatewayRestApi'

```

But that gives me “Internal Error”

Also I have gone throuigh the following github issue

> <https://github.com/serverless/serverless/issues/1955>
>
> \##### Serverless Framework Version: 1.0.0-beta.1.1
> 
> How do I enable CORS so I ca…n access my functions? I can't find anything in the docs, and the CORS plugin seems to not be relevant to the current version of Serverless.

A little bit of help will be appreciated 🙂

---

<div class="post-metadata">

**Author:** ![mithundas79](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/mithundas79/32/4454_2.png) [@mithundas79](https://forum.serverless.com/u/mithundas79)\
**Post date:** [November 29, 2020, 1:30am UTC](https://forum.serverless.com/t/how-to-enable-cors/13228/2 "2020-11-29T01:30:03Z")

</div>

After a lot of head banging came to understand that the above is the correct solution…  
I just used allowed\_headers check box in [https://www.test-cors.org/](https://www.test-cors.org/)  
Once i remove it works fine.
