Alexey2016-05-03 16:36:38
Alexey, 2016-05-03 16:36:38

No 'Access-Control-Allow-Origin' header is present on the requested resource. How to fix the situation?

I use Ionic, Socket.io in the project. The backend is written in node.js.
I'm trying to reach a server located in the Cloud9 cloud using the client.
Gives an error:
XMLHttpRequest cannot load https:/URL. No 'Access-Control-Allow-Origin' header is present on the requested resource. Origin ' ' is therefore not allowed access.
As I understand it, the problem is security, that Chrome does not allow access to an external resource.
1) "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --allow-file-access-from-files --disable-web-security
2) ionic project
"proxies": {
"path": "/chat",
"proxyUrl": "
3) I tried a plugin that disables/enables CORS for Chrome.
Everywhere is the same. Does not help
I contact the server through the service:


.factory('Socket', function (socketFactory) {
  var url = 'https:...';  
  var myIoSocket = io.connect( url );

  mySocket = socketFactory({
    ioSocket: myIoSocket

  return mySocket;

On server:
// Including Express.js
var express = require('express');
// Creating app Express
var app = express();

// Creating server using express and http
var server = require('http').createServer(app);

How to cure this ailment, since going further is not an option ...?
PS Changed the server
var express = require('express');
var app = express();
var http = require('http');
var server = http.createServer(app);

server.on('request', function(req, res) {
res.writeHead(200, {
'Content-Type': 'text/event-stream; charset=utf-8',
'Cache-Control': 'no-cache',
'Access-Control-Allow-Origin': '*'


In this case, I have another error: XMLHttpRequest cannot load https://URL. A wildcard '*' cannot be used in the 'Access-Control-Allow-Origin' header when the credentials flag is true. Origin '' is therefore not allowed access. The credentials mode of an XMLHttpRequest is controlled by the withCredentials attribute.
How to deal with it?

Answer the question

In order to leave comments, you need to log in

3 answer(s)
Alexey Zuev, 2016-05-03

I recently tested the EventSource and accessed cloud9 through angular2. Had the same problem.
I solved by setting Access-Control-Allow-Origin on the server via

res.writeHead(200, {
  'Access-Control-Allow-Origin': '*',
  // 'Access-Control-Allow-Credentials': true 

Another option if express is used
var express = require('express'), 
  cors = require('cors'), 
  app = express();

// или
    origin: true,
    credentials: true

_ _, 2016-05-03

1) ionic proxy should work
2) Chrome launched with the flag should work (but it needs to be launched from scratch - if Chrome is already open, it will just pop into the foreground, without applying the flag, of course)

Error 502, 2016-05-03

Make the server issue this parameter in the header. I had the same crap.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question