# Response to preflight request doesn't pass access control check: The value of the 'Access-Control-Allow-Origin' header in the response must not be the wildcard '*' when the request's credentials mode is 'include'.

- **ID:** `python/fastapi-cors-preflight-credentials`
- **Domain:** python
- **Category:** network_error
- **Verification:** ai_generated
- **Fix Rate:** 80%

## Root Cause

CORSMiddleware configured with allow_origins=['*'] and allow_credentials=True simultaneously.

## Version Compatibility

| Version | Status | Introduced | Deprecated |
|---------|--------|------------|------------|
| 0.100.x | active | — | — |
| 0.110.x | active | — | — |

## Workarounds

1. **** (95% success)
   ```
   app.add_middleware(CORSMiddleware, allow_origins=['https://app.example.com'], allow_credentials=True)
   ```
2. **** (92% success)
   ```
   app.add_middleware(CORSMiddleware, allow_origin_regex=r'https://.*\.example\.com', allow_credentials=True)
   ```

## Dead Ends

- **** — Breaks cookie/auth flows that require credentials. (70% fail)
- **** — Browsers still enforce the CORS check client-side. (85% fail)
