# How to configure CORS

**URL:** https://discuss.tryton.org/t/how-to-configure-cors/2300
**Category:** User
**Created:** [February 7, 2020, 1:16am UTC](https://discuss.tryton.org/t/how-to-configure-cors/2300 "2020-02-07T01:16:31Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![iehoshia](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/iehoshia/32/243_2.png) [@iehoshia](https://discuss.tryton.org/u/iehoshia)
#### Post date: [February 7, 2020, 1:16am UTC](https://discuss.tryton.org/t/how-to-configure-cors/2300/1 "2020-02-07T01:16:32Z")

</div>

Hi,

I was trying trytond 5.2 with gunicorn and works well with tryton but not with sao. I worked before with uwsgi and works without the need to has CORS configured, but with gunicorn doesn’t work.

I was reading about [Configuration file — Tryton server](http://docs.tryton.org/projects/server/en/latest/topics/configuration.html#cors) but I don’t know how to configure it correctly? Is apart from the docs, where can find an example of that?

Thanks in advance.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [February 7, 2020, 9:03am UTC](https://discuss.tryton.org/t/how-to-configure-cors/2300/2 "2020-02-07T09:03:51Z")

</div>

Could you explain your setup and why you think you need CORS?

The configuration of CORS should not be needed for sao as long as it is distributed from the same hostname as trytond (indeed sao should not work otherwise with or without CORS).  
The configuration for CORS should look like:

```ini
[web]
cors =
    example.com
    api.example.com

```

---

<div class="post-metadata">

### Author: ![iehoshia](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/iehoshia/32/243_2.png) [@iehoshia](https://discuss.tryton.org/u/iehoshia)
#### Post date: [February 7, 2020, 10:13pm UTC](https://discuss.tryton.org/t/how-to-configure-cors/2300/3 "2020-02-07T22:13:02Z")

</div>

The setup with uwsgi under emperor.uwsgi.service is:

```
[uwsgi]
socket=/tmp/%n.sock
virtualenv = /opt/test
wsgi=app
module=trytond.application:app
env = TRYTOND_CONFIG=/opt/test/tr.conf
thunder-lock=true
workers = %k
threads = 1
touch-chain-reload = %dreload

```

The setup with gunicorn under systemd is:

```
[Unit]
Description=test gunicorn daemon
After=network.target

[Service]
PIDFile=/run/test_gunicorn/pid
Environment="TRYTOND_CONFIG=/opt/test/tr.conf"
User=www-data
Group=www-data
RuntimeDirectory=test_gunicorn
WorkingDirectory=/opt/test
ExecStartPre=/bin/bash -c 'mkdir -p /run/test_gunicorn; chown www-data:www-data /run/test_gunicorn$
ExecStart=/opt/test/bin/python /opt/test/bin/gunicorn --pid /run/test_gunicorn/pid \
          --bind unix:/run/test_gunicorn/socket trytond.application:app \
          --user=www-data --group=www-data --pythonpath=/opt/test/bin/ \
          --name=test_gunicorn --log-file=/var/log/gunicorn/test.gunicorn.log \
          --timeout=3600 --threads=1 \
          --workers=9 --error-logfile=/var/log/gunicorn/test.gunicorn.error \
          --log-level debug

[Install]
WantedBy=multi-user.target

```

The config with uwsgi works on tryton 5.0, 5.2 and 5.4 and sao 5.0, 5.2, 5.4 using nginx as proxy server.

Using nginx as proxy server the given config with gunicorn works with tryton 5.0, 5.2, 5.4 and sao 5.0. With sao 5.2 and 5.4 gives the follow traceback:

```
File "/opt/test/lib/python3.7/site-packages/trytond/wsgi.py", line 181, in __call__
    return self.wsgi_app(environ, start_response)
  File "/opt/test/lib/python3.7/site-packages/trytond/wsgi.py", line 187, in __call__
    return self.app(environ, start_response)
  File "/opt/test/lib/python3.7/site-packages/trytond/wsgi.py", line 159, in wsgi_app
    abort(HTTPStatus.FORBIDDEN)
  File "/opt/test/lib/python3.7/site-packages/werkzeug/exceptions.py", line 772, in abort
    return _aborter(status, *args, **kwargs)
  File "/opt/test/lib/python3.7/site-packages/werkzeug/exceptions.py", line 753, in __call__
    raise self.mapping[code](*args, **kwargs)
werkzeug.exceptions.Forbidden: 403 Forbidden: You don't have the permission to access the requested resource. It is either read-protected or not readable by the server.

```

I configured cors similar to these but doesn’t work neither.

> [@ced](#):
>
> [web] cors = [example.com](http://example.com) [api.example.com](http://api.example.com)

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [February 7, 2020, 10:57pm UTC](https://discuss.tryton.org/t/how-to-configure-cors/2300/4 "2020-02-07T22:57:58Z")

</div>

I guess you should inspect the `Origin` and `Host` headers of the request received by Tryton.

By the way, I forgot that CORS should contain the schema so it should be like that:

```ini
[web]
cors =
    https://example.com
    https://api.example.com

```

---

<div class="post-metadata">

### Author: ![iehoshia](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/iehoshia/32/243_2.png) [@iehoshia](https://discuss.tryton.org/u/iehoshia)
#### Post date: [February 9, 2020, 3:47pm UTC](https://discuss.tryton.org/t/how-to-configure-cors/2300/5 "2020-02-09T15:47:54Z")

</div>

It works after configure it according to.

> [@ced](#):
>
> [web] cors = [https://example.com](https://example.com) [https://api.example.com](https://api.example.com)

---

<div class="post-metadata">

### Author: ![system](https://discuss-cdn.tryton.org/uploads/default/original/1X/c6f8ec0a40525cdcd50058c734283450a4b3d38b.png) [@system](https://discuss.tryton.org/u/system)
#### Post date: [March 10, 2020, 3:47pm UTC](https://discuss.tryton.org/t/how-to-configure-cors/2300/6 "2020-03-10T15:47:59Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
