# fetchClient and CORS

**URL:** <https://discourse.aurelia.io/t/fetchclient-and-cors/3529>\
**Category:** Help Requests\
**Created:** [May 30, 2020, 7:53pm UTC](https://discourse.aurelia.io/t/fetchclient-and-cors/3529 "2020-05-30T19:53:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rhysshadow](https://yyz1.discourse-cdn.com/flex027/user_avatar/discourse.aurelia.io/rhysshadow/32/1959_2.png) [@rhysshadow](https://discourse.aurelia.io/u/rhysshadow)\
**Post date:** [May 30, 2020, 7:53pm UTC](https://discourse.aurelia.io/t/fetchclient-and-cors/3529/1 "2020-05-30T19:53:28Z")

</div>

I am using the fetchClient to fetch results from a perl script on another domain.

If I don’t do custom headers, I get a CORS error. This is completely reasonable, so I tried to set up custom headers like so:

(based on this link: [https://github.com/aurelia/fetch-client/issues/8](https://github.com/aurelia/fetch-client/issues/8))

```auto
self.httpClient.configure(config => {
          config.withDefaults({
              headers: {
                  'Access-Control-Allow-Origin': '*',
              },
              mode : 'no-cors',
          })
        });

```

When I do this, I get `Unexpected end of input` as an error.

I have also tried:

```auto
self.httpClient.configure(config => {
              config.withDefaults({
                  headers: {
                      'Access-Control-Allow-Origin': '*',
                      'mode' : 'no-cors',
                  },
                  
              })
          });

```

and also:

```auto
self.httpClient.configure(config => {
              config.withDefaults({
                  headers: {
                      'Access-Control-Allow-Origin': '*',
                  },
              'mode' : 'no-cors',
              })
          });

```

If I comment out the headers, I get the CORS error, but eventually it goes away.

My questions are:

1. How do I configure the headers properly?
2. Why is the CORS error going away without me configuring the headers?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![MaximBalaganskiy](https://yyz1.discourse-cdn.com/flex027/user_avatar/discourse.aurelia.io/maximbalaganskiy/32/831_2.png) [@MaximBalaganskiy](https://discourse.aurelia.io/u/MaximBalaganskiy)\
**Post date:** [May 31, 2020, 9:18pm UTC](https://discourse.aurelia.io/t/fetchclient-and-cors/3529/2 "2020-05-31T21:18:41Z")

</div>

`Access-Control-Allow-Origin` must be set by a **server** , not client.

---

<div class="post-metadata">

**Author:** ![rhysshadow](https://yyz1.discourse-cdn.com/flex027/user_avatar/discourse.aurelia.io/rhysshadow/32/1959_2.png) [@rhysshadow](https://discourse.aurelia.io/u/rhysshadow)\
**Post date:** [June 1, 2020, 4:58pm UTC](https://discourse.aurelia.io/t/fetchclient-and-cors/3529/3 "2020-06-01T16:58:49Z")

</div>

Thanks. I figured out how to set the headers in perl, and it seems to be working now.

I did these headers:

```auto
print $cgi->header(-type => "application/json",
                     -charset => "utf-8",
                     -access_control_allow_headers =>'X-Requested-With',
                     -access_control_allow_methods => 'GET,POST,OPTIONS',
                     -access_control_allow_credentials => 'true',
                     -access_control_allow_origin => '*');

```
