Skip to content

JPro CORS Issue #205

Description

@nyzzik

Hello I am using version 2026.1.1. I am trying to use the ServerAPI to create a REST API for my application however I am running into errors with CORS. Is there anywhere that I am able to configure JPro to allow CORS?

Activity

  1. FlorianKirmaier commented on Mar 25, 2026

    @FlorianKirmaier
    Contributor

    Can you share some details?
    I assume you try to access the REST-Api from another tab which has a different domain?

    You should be able to overwrite headers with the ServerAPI.
    We might also offer a way to remove all default headers.
    We will probably soon provide a way, to configure CORS more detailed.

  2. nyzzik commented on Mar 25, 2026

    @nyzzik
    Author

    @FlorianKirmaier

    Yes, I am trying to access the REST-Api from another tab on a different domain however when i try to it complains about CORS. I tried setting the headers manually with the ServerAPI but then it throws an error on the client I am trying to do the request from saying that there is multiple instances of that header in the request. Get requests work fine, anything else though throws the CORS error.
    Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at http://localhost:8081/signals?. (Reason: Multiple CORS header ‘Access-Control-Allow-Origin’ not allowed).

    headers.put("Access-Control-Allow-Origin", "*");
    headers.put("Access-Control-Allow-Methods", "*");
    headers.put("Access-Control-Allow-Headers", "*");

    This is how I am setting the headers and then I am passing the headers HashMap to each of the Responses.

    public static void main(String[] args) {
        gson = new GsonBuilder()
            .excludeFieldsWithModifiers(Modifier.PRIVATE, Modifier.STATIC, Modifier.TRANSIENT, Modifier.VOLATILE)
            .create();
        headers.put("Access-Control-Allow-Origin", "*");
        headers.put("Access-Control-Allow-Methods", "*");
        headers.put("Access-Control-Allow-Headers", "*");
        System.out.println("HMI API is running...");
        ServerAPI.getServerAPI().addRequestHandler(request -> {
            switch (request.getPath()) {
                case PATH_TEST:
                    return textResponse("Test response");
                case PATH_RESTART:
                    DataVAC.restartProg();
                    return textResponse("Restart command executed");
                case PATH_SIGNALS:
                    switch (request.getMethod()) {
                        case "GET":
                            return handleSignalsRequest(request);
                        case "POST":
                            return handleSignalPostRequest(request);
                        default:
                            break;
                    }
                default:
                    return Response.empty();
            }
    
        });
    }
    
    private static Response handleSignalPostRequest(Request request) {
        return Response.of("POST endpoint for signal updates is not implemented yet.".getBytes(StandardCharsets.UTF_8), "text/plain", 501, headers);
    }
  3. nyzzik commented on Mar 25, 2026

    @nyzzik
    Author

    I realized that I was not handling the OPTIONS method.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions