# Login to UI - Not allowed in CORS policy

**URL:** <https://community.dreamfactory.com/t/login-to-ui-not-allowed-in-cors-policy/5351>\
**Category:** App Configuration\
**Tags:** authentication\
**Created:** [March 1, 2022, 5:19pm UTC](https://community.dreamfactory.com/t/login-to-ui-not-allowed-in-cors-policy/5351 "2022-03-01T17:19:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![twoxim](https://avatars.discourse-cdn.com/v4/letter/t/d07c76/32.png) [@twoxim](https://community.dreamfactory.com/u/twoxim)\
**Post date:** [March 1, 2022, 5:19pm UTC](https://community.dreamfactory.com/t/login-to-ui-not-allowed-in-cors-policy/5351/1 "2022-03-01T17:19:35Z")

</div>

5 min to install and 12 hrs to login…I’ve reinstalled 3 times via clone from Git and can’t figure out why I’m getting “Not allowed in CORS policy.”  
I’ve added some version of "Access-Control-Allow-Origin “\*” to:  
the apache site-enabled file  
.htaccess  
bootstrap/app as header(…)  
Created middleware Cors.php  
added to DB as a wildcard

cleared all cache php artisan optimize

I’m not sure what to try next? Anything…I would willing to do again that I’ve tried or even reinstall if I have to.

Debian 10  
Apache latest  
php 7.4  
MySql  
DF 4.10.1

---

<div class="post-metadata">

**Author:** ![twoxim](https://avatars.discourse-cdn.com/v4/letter/t/d07c76/32.png) [@twoxim](https://community.dreamfactory.com/u/twoxim)\
**Post date:** [March 4, 2022, 2:54pm UTC](https://community.dreamfactory.com/t/login-to-ui-not-allowed-in-cors-policy/5351/2 "2022-03-04T14:54:08Z")

</div>

OK, after 20+ hours I was finally able to log in with not a fix but a work around so I can get my clients API setup.

I commented out lines 44-46 of vendor \> barryvdh \> lavavel-cors \> src \> HandleCors.php  
Works for now but clearly I need to go back a find out the root cause.

Hopefully that will save someone 20hrs of work! 😊
