# Access to XMLHttpRequest at 'http://api.local/users' from origin 'http://frontend.local' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.

- **ID:** `python/flask-cors-no-access-control-allow-origin`
- **Domain:** python
- **Category:** network_error
- **Verification:** ai_generated
- **Fix Rate:** 80%

## Root Cause

Server did not return CORS headers for the origin, or flask-cors was configured with resources that exclude the path.

## Version Compatibility

| Version | Status | Introduced | Deprecated |
|---------|--------|------------|------------|
| 4.0.x | active | — | — |

## Workarounds

1. **** (95% success)
   ```
   from flask_cors import CORS
CORS(app, resources={r"/api/*": {"origins": "https://frontend.local"}}, supports_credentials=True)
   ```
2. **** (90% success)
   ```
   Ensure `@app.after_request` adds headers even on error: def add_cors(resp): resp.headers['Access-Control-Allow-Origin']=origin; return resp
   ```

## Dead Ends

- **** — Fails with credentials=true; browsers reject wildcard with credentials. (80% fail)
- **** — Error responses (4xx/5xx) still lack headers; browser blocks them. (75% fail)
