# CORS, appending portnum

**URL:** <https://community.dreamfactory.com/t/cors-appending-portnum/359>\
**Category:** App Configuration\
**Created:** [September 16, 2014, 11:38am UTC](https://community.dreamfactory.com/t/cors-appending-portnum/359 "2014-09-16T11:38:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dag](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.dreamfactory.com/dag/32/105_2.png) [@dag](https://community.dreamfactory.com/u/dag)\
**Post date:** [September 16, 2014, 11:38am UTC](https://community.dreamfactory.com/t/cors-appending-portnum/359/1 "2014-09-16T11:38:07Z")

</div>

I have my dsp setup at [dsp.foo.com:8080](http://dsp.foo.com:8080).  
I have my webfiles hosted at [dev.foo.com](http://dev.foo.com) (same server).

The error: XMLHttpRequest cannot load [http://dsp.foo.com:8080/rest/api\_docs](http://dsp.foo.com:8080/rest/api_docs). The ‘Access-Control-Allow-Origin’ header has a value ‘[http://dev.foo.com:8080](http://dev.foo.com:8080)’ that is not equal to the supplied origin. Origin ‘[http://dev.foo.com](http://dev.foo.com)’ is therefore not allowed access.

In the dsp-config I have setup CORS with \* for all methods (and enabled).

The problem is that the Access-Control-Allow-Origin automatically appends the portnumber of the dsp (:8080) and therefore the origin is not the same. But I never try to access the dsp from :8080, its origin is [http://dev.foo.com](http://dev.foo.com) !

If I use curl and forge a request and specify -H ‘Origin: [http://dsp.foo.com](http://dsp.foo.com)’ the response is: “Access-Control-Allow-Origin: [http://foo.com:8080](http://foo.com:8080)”. This must clearly be wrong ?

If I specify a custom port it uses this correctly: -H ‘Origin: [http://dsp.foo.com:8181](http://dsp.foo.com:8181)’ , response: “Access-Control-Allow-Origin: [http://foo.com:8181](http://foo.com:8181)”

I dont know where to start debugging this, the dreamfactory/htdocs/storage/cors.config.json file is correct.

/Dag

---

<div class="post-metadata">

**Author:** ![Jason](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.dreamfactory.com/jason/32/1194_2.png) [@Jason](https://community.dreamfactory.com/u/Jason)\
**Post date:** [September 17, 2014, 12:17pm UTC](https://community.dreamfactory.com/t/cors-appending-portnum/359/2 "2014-09-17T12:17:24Z")

</div>

So you have a reverse proxy, and you’re using one of the javascript SDKs? Is that correct?

---

<div class="post-metadata">

**Author:** ![dag](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.dreamfactory.com/dag/32/105_2.png) [@dag](https://community.dreamfactory.com/u/dag)\
**Post date:** [September 17, 2014, 12:47pm UTC](https://community.dreamfactory.com/t/cors-appending-portnum/359/3 "2014-09-17T12:47:19Z")

</div>

no, there is no proxying, the dsp is setup at server:8080 and the web is served from server:80.  
When the dsp creates the Access-Control-Allow-Origin header it opens for origin ‘server:8080’ but this fails because the origin is not server:8080 but ‘server’ or ‘server:80’

The Access-Control-Allow-Origin header is set to [http://server:8080](http://server:8080), when it really should be [http://server](http://server)

I have made a quick dirty workaround in vendor/dreamfactory/lib-php-common-platform/src/Yii/Components/PlatformWebApplication.php to prevent it from appending the dsp-port-nummer to the client-origin.

---

<div class="post-metadata">

**Author:** ![Jason](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.dreamfactory.com/jason/32/1194_2.png) [@Jason](https://community.dreamfactory.com/u/Jason)\
**Post date:** [September 22, 2014, 1:13am UTC](https://community.dreamfactory.com/t/cors-appending-portnum/359/4 "2014-09-22T01:13:02Z")

</div>

Which SDK are you using ?

---

<div class="post-metadata">

**Author:** ![dag](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.dreamfactory.com/dag/32/105_2.png) [@dag](https://community.dreamfactory.com/u/dag)\
**Post date:** [September 22, 2014, 6:53am UTC](https://community.dreamfactory.com/t/cors-appending-portnum/359/5 "2014-09-22T06:53:58Z")

</div>

This behaviour can be observed sdk-independently with just using curl and setting the Origin-header manually.

My app uses the angular-dreamfactory module.

---

<div class="post-metadata">

**Author:** ![Mark](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.dreamfactory.com/mark/32/69_2.png) [@Mark](https://community.dreamfactory.com/u/Mark)\
**Post date:** [October 7, 2014, 4:21pm UTC](https://community.dreamfactory.com/t/cors-appending-portnum/359/6 "2014-10-07T16:21:53Z")

</div>

**Upgrade Notice**

Reaching out to let everyone know about the fix in **DreamFactory Service Platform version 1.8** has been pushed to github.

[DreamFactory Software on Github](https://github.com/dreamfactorysoftware)

There is also the **[Wiki Upgrade Page](https://github.com/dreamfactorysoftware/dsp-core/wiki/Product-Upgrades)** where you can find how to upgrade based on your specific OS.

Thanks,

- Mark
