python network_error ai_generated true

Access to XMLHttpRequest at 'http://api.local/users' from origin 'http://frontend.local' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.

ID: python/flask-cors-no-access-control-allow-origin

Also available as: JSON · Markdown · 中文
80%Fix Rate
86%Confidence
0Evidence
2024-11-05First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
4.0.x active — — —

Root Cause

Server did not return CORS headers for the origin, or flask-cors was configured with resources that exclude the path.

generic

中文

服务器未为来源返回 CORS 头,或 flask-cors 配置的 resources 排除了该路径。

Workarounds

  1. 95% success
    from flask_cors import CORS
    CORS(app, resources={r"/api/*": {"origins": "https://frontend.local"}}, supports_credentials=True)
  2. 90% success
    Ensure `@app.after_request` adds headers even on error: def add_cors(resp): resp.headers['Access-Control-Allow-Origin']=origin; return resp

Dead Ends

Common approaches that don't work:

  1. 80% fail

    Fails with credentials=true; browsers reject wildcard with credentials.

  2. 75% fail

    Error responses (4xx/5xx) still lack headers; browser blocks them.