# CORS Error when Sending POST requests to Express Backend

**URL:** <https://community.firebasestudio.dev/t/cors-error-when-sending-post-requests-to-express-backend/6246>\
**Category:** General\
**Created:** [October 15, 2024, 4:48am UTC](https://community.firebasestudio.dev/t/cors-error-when-sending-post-requests-to-express-backend/6246 "2024-10-15T04:48:19Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aditya\_Payanadan](https://sea2.discourse-cdn.com/flex002/user_avatar/community.firebasestudio.dev/aditya_payanadan/32/2639_2.png) [@Aditya\_Payanadan](https://community.firebasestudio.dev/u/Aditya_Payanadan)\
**Post date:** [October 15, 2024, 4:48am UTC](https://community.firebasestudio.dev/t/cors-error-when-sending-post-requests-to-express-backend/6246/1 "2024-10-15T04:48:19Z")

</div>

Hello everybody,  
I am trying to create a quiz app using Gemini API, and am using an express backend for this project. When trying to send a POST request from my frontend javascript to the express server, I constantly get the error:

Blockquote  
Access to fetch at ‘[https://3000-idx-aa-1727415100211.cluster-fu5knmr55rd44vy7k7pxk74ams.cloudworkstations.dev/](https://3000-idx-aa-1727415100211.cluster-fu5knmr55rd44vy7k7pxk74ams.cloudworkstations.dev/)’ from origin ‘[https://9000-idx-aa-1727415100211.cluster-fu5knmr55rd44vy7k7pxk74ams.cloudworkstations.dev](https://9000-idx-aa-1727415100211.cluster-fu5knmr55rd44vy7k7pxk74ams.cloudworkstations.dev)’ has been blocked by CORS policy: Response to preflight request doesn’t pass access control check: The value of the ‘Access-Control-Allow-Credentials’ header in the response is ‘’ which must be ‘true’ when the request’s credentials mode is ‘include’.

> Blockquote

I have tried many methods and have also explicitly set options for the preflight request using cors. I am wondering if it is an issue with referring to the frontend URL? I have also heard this is an ongoing issue so any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![kirupa](https://sea2.discourse-cdn.com/flex002/user_avatar/community.firebasestudio.dev/kirupa/32/4_2.png) [@kirupa](https://community.firebasestudio.dev/u/kirupa)\
**Post date:** [October 15, 2024, 4:49am UTC](https://community.firebasestudio.dev/t/cors-error-when-sending-post-requests-to-express-backend/6246/2 "2024-10-15T04:49:36Z")

</div>

Are you running into this issue by any chance?

> [@Early preview of public ports!](https://community.firebasestudio.dev/t/early-preview-of-public-ports/1911/17):
>
> Found the problem! Thanks so much for helping us identify it. In short, one of our proxies is removing CORS headers (e.g. Access-Control-Allow-Origin) in the HTTP response for the browser’s OPTIONS request (aka “preflight”, which are used for POST requests). I haven’t found a good workaround yet, but we’ll follow up in [the bug you filed](https://issuetracker.google.com/issues/369331504) (thank you!). Hopefully this is something we can resolve shortly. EDIT: I updated the bug title and added repro steps, will now follow up with our infra teams …
