DataPower

DataPower

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

Getting any origin value (set in Request headers) in "Access-Control-Allow -Origin" response headers for 404 and 405 error code

  • 1.  Getting any origin value (set in Request headers) in "Access-Control-Allow -Origin" response headers for 404 and 405 error code

    Posted Tue July 04, 2023 12:27 PM

    Hello Team,

    When we set "Origin" value in request Headers, receive same Origin value in "Access-Control-Allow -Origin" response headers for "404 and 405" error code which is vulnerable. We need to set value for "Access-Control-Allow -Origin" in response Headers.

    We have set value in DataPower which is reflect for "200,401,500" error/success codes, but for "404 and 405" error code it respond back as value set in requestHeaders or "*".

    As observed in logs, We have not received any logs for "404 and 405" error code  in Analytics logs, only received hits in DataPower server.

    Please suggest how to set "Access-Control-Allow -Origin" value in DataPower for "404 & 405" error code.

    404: Requested URI Path not Found

    405: Method type Not allowed



    ------------------------------
    Jyoti Yadav
    ------------------------------


  • 2.  RE: Getting any origin value (set in Request headers) in "Access-Control-Allow -Origin" response headers for 404 and 405 error code

    Posted Thu August 03, 2023 11:46 AM

    Jyoti,

    I'm so sorry I missed this back when posted.  Have you resolved this issue?



    ------------------------------
    Joseph Morgan
    ------------------------------



  • 3.  RE: Getting any origin value (set in Request headers) in "Access-Control-Allow -Origin" response headers for 404 and 405 error code

    Posted Tue August 22, 2023 12:22 PM

    Hello Joseph,

    No yet, please help on solution for same issue. We need to set "Access-Control-Allow -Origin" for "429- Rate limit" error code as well.

    Thank you in advance.



    ------------------------------
    Jyoti Yadav
    ------------------------------



  • 4.  RE: Getting any origin value (set in Request headers) in "Access-Control-Allow -Origin" response headers for 404 and 405 error code

    Posted Tue August 22, 2023 01:25 PM

    OK.  How are you handling the header now for the 200, 401 & 500 codes?



    ------------------------------
    Joseph Morgan
    ------------------------------