# Access to fetch at 'http://api.local/x' from origin 'http://web.local' has been blocked by CORS policy: Response to preflight request doesn't pass access control check

- **ID:** `python/flask-cors-blocked-preflight`
- **Domain:** python
- **Category:** network_error
- **Verification:** ai_generated
- **Fix Rate:** 80%

## Root Cause

Flask-CORS not configured for the route, or OPTIONS preflight handled by a catch-all before CORS middleware.

## Version Compatibility

| Version | Status | Introduced | Deprecated |
|---------|--------|------------|------------|
| 4.x | active | — | — |
| 5.x | active | — | — |

## Workarounds

1. **** (92% success)
   ```
   CORS(app, resources={r'/api/*': {'origins': ['http://web.local']}}, supports_credentials=True)
   ```
2. **** (90% success)
   ```
   app = Flask(__name__)\nCORS(app)\n# then register blueprints
   ```

## Dead Ends

- **** — Preflight OPTIONS never reaches the view; browser blocks it earlier. (75% fail)
- **** — If credentials used, wildcard origin is rejected by the browser. (70% fail)
