HSTS redirect sets Origin to 'null'Are there any browsers that set the origin header to “null” for privacy-sensitive contexts?AJAX call following 302 redirect sets origin to nullHow do I redirect to another webpage?Access-Control-Allow-Origin Multiple Origin Domains?XmlHttpRequest error: Origin null is not allowed by Access-Control-Allow-OriginOrigin is not allowed by Access-Control-Allow-OriginHow does Access-Control-Allow-Origin header work?AngularJS performs an OPTIONS HTTP request for a cross-origin resourceNo 'Access-Control-Allow-Origin' - Node / Apache Port IssueWhy does my JavaScript code get a “No 'Access-Control-Allow-Origin' header is present on the requested resource” error when Postman does not?Font from origin has been blocked from loading by Cross-Origin Resource Sharing policyResponse to preflight request doesn't pass access control check
Duplicate instruments in unison in an orchestra
Is gzip atomic?
Do Bayesian credible intervals treat the estimated parameter as a random variable?
HJM in infinite dimensions
"There were either twelve sexes or none."
Prevent use of CNAME record for untrusted domain
How does encoder decoder network works?
How were medieval castles built in swamps or marshes without draining them?
"fF" letter combination seems to be typeset strangely or incorrectly
Breaker Mapping Questions
Prove your innocence
How do I get toddlers to stop asking for food every hour?
Immediate Smaller Element Time Limit Exceeded
Talk interpreter
When one problem is added to the previous one
Tex Quotes(UVa 272)
Very slow boot time and poor perfomance
Why are non-collision-resistant hash functions considered insecure for signing self-generated information
Joining lists with same elements
Does ostensible/specious make sense in this sentence?
Architectural feasibility of a tiered circular stone keep
To get so rich that you are not in need of anymore money
Handling Disruptive Student on the Autism Spectrum
Why do proofs of Bernoulli's equation assume that forces on opposite ends point in different directions?
HSTS redirect sets Origin to 'null'
Are there any browsers that set the origin header to “null” for privacy-sensitive contexts?AJAX call following 302 redirect sets origin to nullHow do I redirect to another webpage?Access-Control-Allow-Origin Multiple Origin Domains?XmlHttpRequest error: Origin null is not allowed by Access-Control-Allow-OriginOrigin is not allowed by Access-Control-Allow-OriginHow does Access-Control-Allow-Origin header work?AngularJS performs an OPTIONS HTTP request for a cross-origin resourceNo 'Access-Control-Allow-Origin' - Node / Apache Port IssueWhy does my JavaScript code get a “No 'Access-Control-Allow-Origin' header is present on the requested resource” error when Postman does not?Font from origin has been blocked from loading by Cross-Origin Resource Sharing policyResponse to preflight request doesn't pass access control check
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;
Client tries to access http://example.com/token/
but example.com
had HSTS header and clients browser redirects (307) to https://example.com/token/
with Origin set to 'null' which is being blocked by CORS, but 'null' cannot be in our allowed cors origin.
The error:
Access to XMLHttpRequest at https://example.com/token/
(redirected from http://example.com/token/
) from origin 'null' has been blocked by CORS policy
How can the issue be solved?
redirect cors http-headers hsts
add a comment |
Client tries to access http://example.com/token/
but example.com
had HSTS header and clients browser redirects (307) to https://example.com/token/
with Origin set to 'null' which is being blocked by CORS, but 'null' cannot be in our allowed cors origin.
The error:
Access to XMLHttpRequest at https://example.com/token/
(redirected from http://example.com/token/
) from origin 'null' has been blocked by CORS policy
How can the issue be solved?
redirect cors http-headers hsts
1
https://example.com
is a different origin thanhttp://example.com
. And when a request is redirected across origins, the browser sets the origin of the request to null. That behavior is required by the Fetch spec. The browser marks the origin as “tainted” in that case. See fetch.spec.whatwg.org/… and stackoverflow.com/q/30193851/441757 and stackoverflow.com/a/22625354/441757
– sideshowbarker
Mar 28 at 1:21
add a comment |
Client tries to access http://example.com/token/
but example.com
had HSTS header and clients browser redirects (307) to https://example.com/token/
with Origin set to 'null' which is being blocked by CORS, but 'null' cannot be in our allowed cors origin.
The error:
Access to XMLHttpRequest at https://example.com/token/
(redirected from http://example.com/token/
) from origin 'null' has been blocked by CORS policy
How can the issue be solved?
redirect cors http-headers hsts
Client tries to access http://example.com/token/
but example.com
had HSTS header and clients browser redirects (307) to https://example.com/token/
with Origin set to 'null' which is being blocked by CORS, but 'null' cannot be in our allowed cors origin.
The error:
Access to XMLHttpRequest at https://example.com/token/
(redirected from http://example.com/token/
) from origin 'null' has been blocked by CORS policy
How can the issue be solved?
redirect cors http-headers hsts
redirect cors http-headers hsts
edited Mar 27 at 20:56
Teodor Scorpan
asked Mar 27 at 18:40
Teodor ScorpanTeodor Scorpan
4641 gold badge5 silver badges15 bronze badges
4641 gold badge5 silver badges15 bronze badges
1
https://example.com
is a different origin thanhttp://example.com
. And when a request is redirected across origins, the browser sets the origin of the request to null. That behavior is required by the Fetch spec. The browser marks the origin as “tainted” in that case. See fetch.spec.whatwg.org/… and stackoverflow.com/q/30193851/441757 and stackoverflow.com/a/22625354/441757
– sideshowbarker
Mar 28 at 1:21
add a comment |
1
https://example.com
is a different origin thanhttp://example.com
. And when a request is redirected across origins, the browser sets the origin of the request to null. That behavior is required by the Fetch spec. The browser marks the origin as “tainted” in that case. See fetch.spec.whatwg.org/… and stackoverflow.com/q/30193851/441757 and stackoverflow.com/a/22625354/441757
– sideshowbarker
Mar 28 at 1:21
1
1
https://example.com
is a different origin than http://example.com
. And when a request is redirected across origins, the browser sets the origin of the request to null. That behavior is required by the Fetch spec. The browser marks the origin as “tainted” in that case. See fetch.spec.whatwg.org/… and stackoverflow.com/q/30193851/441757 and stackoverflow.com/a/22625354/441757– sideshowbarker
Mar 28 at 1:21
https://example.com
is a different origin than http://example.com
. And when a request is redirected across origins, the browser sets the origin of the request to null. That behavior is required by the Fetch spec. The browser marks the origin as “tainted” in that case. See fetch.spec.whatwg.org/… and stackoverflow.com/q/30193851/441757 and stackoverflow.com/a/22625354/441757– sideshowbarker
Mar 28 at 1:21
add a comment |
0
active
oldest
votes
Your Answer
StackExchange.ifUsing("editor", function ()
StackExchange.using("externalEditor", function ()
StackExchange.using("snippets", function ()
StackExchange.snippets.init();
);
);
, "code-snippets");
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "1"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55384411%2fhsts-redirect-sets-origin-to-null%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
0
active
oldest
votes
0
active
oldest
votes
active
oldest
votes
active
oldest
votes
Is this question similar to what you get asked at work? Learn more about asking and sharing private information with your coworkers using Stack Overflow for Teams.
Is this question similar to what you get asked at work? Learn more about asking and sharing private information with your coworkers using Stack Overflow for Teams.
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55384411%2fhsts-redirect-sets-origin-to-null%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
1
https://example.com
is a different origin thanhttp://example.com
. And when a request is redirected across origins, the browser sets the origin of the request to null. That behavior is required by the Fetch spec. The browser marks the origin as “tainted” in that case. See fetch.spec.whatwg.org/… and stackoverflow.com/q/30193851/441757 and stackoverflow.com/a/22625354/441757– sideshowbarker
Mar 28 at 1:21