python
network_error
ai_generated
true
Access to XMLHttpRequest at 'http://api.local/users' from origin 'http://frontend.local' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.
ID: python/flask-cors-no-access-control-allow-origin
80%Fix Rate
86%Confidence
0Evidence
2024-11-05First Seen
Version Compatibility
| Version | Status | Introduced | Deprecated | Notes |
|---|---|---|---|---|
| 4.0.x | active | — | — | — |
Root Cause
Server did not return CORS headers for the origin, or flask-cors was configured with resources that exclude the path.
generic中文
服务器未为来源返回 CORS 头,或 flask-cors 配置的 resources 排除了该路径。
Workarounds
-
95% success
from flask_cors import CORS CORS(app, resources={r"/api/*": {"origins": "https://frontend.local"}}, supports_credentials=True) -
90% success
Ensure `@app.after_request` adds headers even on error: def add_cors(resp): resp.headers['Access-Control-Allow-Origin']=origin; return resp
Dead Ends
Common approaches that don't work:
-
80% fail
Fails with credentials=true; browsers reject wildcard with credentials.
-
75% fail
Error responses (4xx/5xx) still lack headers; browser blocks them.