# HTTP/1.1 400 Bad Request
CORS preflight request failed: missing Access-Control-Request-Method

- **ID:** `python/fastapi-cors-preflight-400`
- **Domain:** python
- **Category:** network_error
- **Verification:** ai_generated
- **Fix Rate:** 80%

## Root Cause

CORSMiddleware not added, or added after other middleware that short-circuits OPTIONS; or allow_methods excludes the method.

## Version Compatibility

| Version | Status | Introduced | Deprecated |
|---------|--------|------------|------------|
| 0.100.x | active | — | — |
| 0.110.x | active | — | — |

## Workarounds

1. **** (95% success)
   ```
   app.add_middleware(CORSMiddleware, allow_origins=['https://app.example.com'], allow_methods=['GET','POST','PUT','DELETE','OPTIONS'], allow_headers=['*'], allow_credentials=True) — add FIRST before other middlewares.
   ```
2. **** (90% success)
   ```
   Verify order: middleware added later wraps earlier ones; CORS should be outermost.
   ```

## Dead Ends

- **** — Tedious and misses middleware ordering; CORSMiddleware already handles preflight. (80% fail)
- **** — Browsers reject wildcard with credentials. (90% fail)
