# Request header field X-Requested-With is not allowed by Access-Control-Allow-Headers. (CORS )

**URL:** <https://forum.mautic.org/t/request-header-field-x-requested-with-is-not-allowed-by-access-control-allow-headers-cors/6304>\
**Category:** Product Support\
**Created:** [October 21, 2016, 12:42pm UTC](https://forum.mautic.org/t/request-header-field-x-requested-with-is-not-allowed-by-access-control-allow-headers-cors/6304 "2016-10-21T12:42:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Farhaddc](https://avatars.discourse-cdn.com/v4/letter/f/e480ec/32.png) [@Farhaddc](https://forum.mautic.org/u/Farhaddc)\
**Post date:** [October 21, 2016, 12:42pm UTC](https://forum.mautic.org/t/request-header-field-x-requested-with-is-not-allowed-by-access-control-allow-headers-cors/6304/1 "2016-10-21T12:42:21Z")

</div>

I have a main domain and a subdomain (where actual mautic is installed), unfortunately, I have a cross-origin HTTP request problem if mautic is setup within a subdomain. When I load the [example.com](http://example.com) I get the following errors in Safari Console:

Code:

Failed to load resource: Origin https://example.com is not allowed by Access-Control-Allow-Origin. XMLHttpRequest cannot load https://subdomain.example.com/mtc. Origin https://example.com is not allowed by Access-Control-Allow-Origin.

  
Which make sense for security reason.  
  
So, I add

Code:

header set Access-Control-Allow-Origin: https://example.com

to https://subdomain.example.com

Code:

/etc/httpd/conf/httpd.conf

file. Thanks to this [article about CORS on MDN](https://developer.mozilla.org/en-US/docs/Web/HTTP/Access_control_CORS). But, now I get the following error:  

Code:

Failed to load resource: Credentials flag is true, but Access-Control-Allow-Credentials is not "true". MLHttpRequest cannot load https://subdomain.example.com/mtc. Credentials flag is true, but Access-Control-Allow-Credentials is not "true".

  
Then, I add

Code:

header set Access-Control-Allow-Credentials: true

to

Code:

/etc/httpd/conf/httpd.conf

file. But I still get an error:

Code:

Failed to load resource: Request header field X-Requested-With is not allowed by Access-Control-Allow-Headers. XMLHttpRequest cannot load https://subdomain.example.com/mtc. Request header field X-Requested-With is not allowed by Access-Control-Allow-Headers.

  
And, this is where I'm stuck, Can someone help me? Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Farhaddc](https://avatars.discourse-cdn.com/v4/letter/f/e480ec/32.png) [@Farhaddc](https://forum.mautic.org/u/Farhaddc)\
**Post date:** [October 21, 2016, 12:42pm UTC](https://forum.mautic.org/t/request-header-field-x-requested-with-is-not-allowed-by-access-control-allow-headers-cors/6304/2 "2016-10-21T12:42:21Z")

</div>

I have a main domain and a subdomain (where actual mautic is installed), unfortunately, I have a cross-origin HTTP request problem if mautic is setup within a subdomain. When I load the [example.com](http://example.com) I get the following errors in Safari Console:

`Failed to load resource: Origin https://example.com is not allowed by Access-Control-Allow-Origin.
XMLHttpRequest cannot load https://subdomain.example.com/mtc. Origin https://example.com is not allowed by Access-Control-Allow-Origin.`

Which make sense for security reason.

So, I add `header set Access-Control-Allow-Origin: https://example.com` to [https://subdomain.example.com](https://subdomain.example.com) `/etc/httpd/conf/httpd.conf` file. Thanks to this [article about CORS on MDN](https://developer.mozilla.org/en-US/docs/Web/HTTP/Access_control_CORS). But, now I get the following error:

`Failed to load resource: Credentials flag is true, but Access-Control-Allow-Credentials is not "true".
MLHttpRequest cannot load https://subdomain.example.com/mtc. Credentials flag is true, but Access-Control-Allow-Credentials is not "true".`

Then, I add `header set Access-Control-Allow-Credentials: true` to `/etc/httpd/conf/httpd.conf` file. But I still get an error:

`Failed to load resource: Request header field X-Requested-With is not allowed by Access-Control-Allow-Headers.
XMLHttpRequest cannot load https://subdomain.example.com/mtc. Request header field X-Requested-With is not allowed by Access-Control-Allow-Headers.`

And, this is where I’m stuck, Can someone help me? Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Farhaddc](https://avatars.discourse-cdn.com/v4/letter/f/e480ec/32.png) [@Farhaddc](https://forum.mautic.org/u/Farhaddc)\
**Post date:** [October 22, 2016, 2:10pm UTC](https://forum.mautic.org/t/request-header-field-x-requested-with-is-not-allowed-by-access-control-allow-headers-cors/6304/3 "2016-10-22T14:10:12Z")

</div>

I find the solution to this issue. What you need to do is set the Origin, Headers, and Credentials. I miss the “Headers” section which I didn’t specify in my `httpd.conf`. Here is the complete configuration:

` Header set Access-Control-Allow-Origin: https://example.com
    Header set Access-Control-Allow-Headers "Origin, X-Requested-With, Content-Type, Accept"
    Header set Access-Control-Allow-Credentials: true`

---

<div class="post-metadata">

**Author:** ![williamknn](https://avatars.discourse-cdn.com/v4/letter/w/9fc29f/32.png) [@williamknn](https://forum.mautic.org/u/williamknn)\
**Post date:** [September 22, 2017, 3:25am UTC](https://forum.mautic.org/t/request-header-field-x-requested-with-is-not-allowed-by-access-control-allow-headers-cors/6304/4 "2017-09-22T03:25:21Z")

</div>

Farhadd, where exactly have you put this headers in httpd.conf? I tried putting these lines in the bottom of the document but with no success.
