HSTS redirect sets Origin to 'null'Are there any browsers that set the origin header to “null” for privacy-sensitive contexts?AJAX call following 302 redirect sets origin to nullHow do I redirect to another webpage?Access-Control-Allow-Origin Multiple Origin Domains?XmlHttpRequest error: Origin null is not allowed by Access-Control-Allow-OriginOrigin is not allowed by Access-Control-Allow-OriginHow does Access-Control-Allow-Origin header work?AngularJS performs an OPTIONS HTTP request for a cross-origin resourceNo 'Access-Control-Allow-Origin' - Node / Apache Port IssueWhy does my JavaScript code get a “No 'Access-Control-Allow-Origin' header is present on the requested resource” error when Postman does not?Font from origin has been blocked from loading by Cross-Origin Resource Sharing policyResponse to preflight request doesn't pass access control check

Duplicate instruments in unison in an orchestra

Is gzip atomic?

Do Bayesian credible intervals treat the estimated parameter as a random variable?

HJM in infinite dimensions

"There were either twelve sexes or none."

Prevent use of CNAME record for untrusted domain

How does encoder decoder network works?

How were medieval castles built in swamps or marshes without draining them?

"fF" letter combination seems to be typeset strangely or incorrectly

Breaker Mapping Questions

Prove your innocence

How do I get toddlers to stop asking for food every hour?

Immediate Smaller Element Time Limit Exceeded

Talk interpreter

When one problem is added to the previous one

Tex Quotes(UVa 272)

Very slow boot time and poor perfomance

Why are non-collision-resistant hash functions considered insecure for signing self-generated information

Joining lists with same elements

Does ostensible/specious make sense in this sentence?

Architectural feasibility of a tiered circular stone keep

To get so rich that you are not in need of anymore money

Handling Disruptive Student on the Autism Spectrum

Why do proofs of Bernoulli's equation assume that forces on opposite ends point in different directions?



HSTS redirect sets Origin to 'null'


Are there any browsers that set the origin header to “null” for privacy-sensitive contexts?AJAX call following 302 redirect sets origin to nullHow do I redirect to another webpage?Access-Control-Allow-Origin Multiple Origin Domains?XmlHttpRequest error: Origin null is not allowed by Access-Control-Allow-OriginOrigin is not allowed by Access-Control-Allow-OriginHow does Access-Control-Allow-Origin header work?AngularJS performs an OPTIONS HTTP request for a cross-origin resourceNo 'Access-Control-Allow-Origin' - Node / Apache Port IssueWhy does my JavaScript code get a “No 'Access-Control-Allow-Origin' header is present on the requested resource” error when Postman does not?Font from origin has been blocked from loading by Cross-Origin Resource Sharing policyResponse to preflight request doesn't pass access control check






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;








1















Client tries to access http://example.com/token/ but example.com had HSTS header and clients browser redirects (307) to https://example.com/token/ with Origin set to 'null' which is being blocked by CORS, but 'null' cannot be in our allowed cors origin.



The error:



Access to XMLHttpRequest at https://example.com/token/ (redirected from http://example.com/token/) from origin 'null' has been blocked by CORS policy



How can the issue be solved?










share|improve this question





















  • 1





    https://example.com is a different origin than http://example.com. And when a request is redirected across origins, the browser sets the origin of the request to null. That behavior is required by the Fetch spec. The browser marks the origin as “tainted” in that case. See fetch.spec.whatwg.org/… and stackoverflow.com/q/30193851/441757 and stackoverflow.com/a/22625354/441757

    – sideshowbarker
    Mar 28 at 1:21

















1















Client tries to access http://example.com/token/ but example.com had HSTS header and clients browser redirects (307) to https://example.com/token/ with Origin set to 'null' which is being blocked by CORS, but 'null' cannot be in our allowed cors origin.



The error:



Access to XMLHttpRequest at https://example.com/token/ (redirected from http://example.com/token/) from origin 'null' has been blocked by CORS policy



How can the issue be solved?










share|improve this question





















  • 1





    https://example.com is a different origin than http://example.com. And when a request is redirected across origins, the browser sets the origin of the request to null. That behavior is required by the Fetch spec. The browser marks the origin as “tainted” in that case. See fetch.spec.whatwg.org/… and stackoverflow.com/q/30193851/441757 and stackoverflow.com/a/22625354/441757

    – sideshowbarker
    Mar 28 at 1:21













1












1








1








Client tries to access http://example.com/token/ but example.com had HSTS header and clients browser redirects (307) to https://example.com/token/ with Origin set to 'null' which is being blocked by CORS, but 'null' cannot be in our allowed cors origin.



The error:



Access to XMLHttpRequest at https://example.com/token/ (redirected from http://example.com/token/) from origin 'null' has been blocked by CORS policy



How can the issue be solved?










share|improve this question
















Client tries to access http://example.com/token/ but example.com had HSTS header and clients browser redirects (307) to https://example.com/token/ with Origin set to 'null' which is being blocked by CORS, but 'null' cannot be in our allowed cors origin.



The error:



Access to XMLHttpRequest at https://example.com/token/ (redirected from http://example.com/token/) from origin 'null' has been blocked by CORS policy



How can the issue be solved?







redirect cors http-headers hsts






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Mar 27 at 20:56







Teodor Scorpan

















asked Mar 27 at 18:40









Teodor ScorpanTeodor Scorpan

4641 gold badge5 silver badges15 bronze badges




4641 gold badge5 silver badges15 bronze badges










  • 1





    https://example.com is a different origin than http://example.com. And when a request is redirected across origins, the browser sets the origin of the request to null. That behavior is required by the Fetch spec. The browser marks the origin as “tainted” in that case. See fetch.spec.whatwg.org/… and stackoverflow.com/q/30193851/441757 and stackoverflow.com/a/22625354/441757

    – sideshowbarker
    Mar 28 at 1:21












  • 1





    https://example.com is a different origin than http://example.com. And when a request is redirected across origins, the browser sets the origin of the request to null. That behavior is required by the Fetch spec. The browser marks the origin as “tainted” in that case. See fetch.spec.whatwg.org/… and stackoverflow.com/q/30193851/441757 and stackoverflow.com/a/22625354/441757

    – sideshowbarker
    Mar 28 at 1:21







1




1





https://example.com is a different origin than http://example.com. And when a request is redirected across origins, the browser sets the origin of the request to null. That behavior is required by the Fetch spec. The browser marks the origin as “tainted” in that case. See fetch.spec.whatwg.org/… and stackoverflow.com/q/30193851/441757 and stackoverflow.com/a/22625354/441757

– sideshowbarker
Mar 28 at 1:21





https://example.com is a different origin than http://example.com. And when a request is redirected across origins, the browser sets the origin of the request to null. That behavior is required by the Fetch spec. The browser marks the origin as “tainted” in that case. See fetch.spec.whatwg.org/… and stackoverflow.com/q/30193851/441757 and stackoverflow.com/a/22625354/441757

– sideshowbarker
Mar 28 at 1:21












0






active

oldest

votes










Your Answer






StackExchange.ifUsing("editor", function ()
StackExchange.using("externalEditor", function ()
StackExchange.using("snippets", function ()
StackExchange.snippets.init();
);
);
, "code-snippets");

StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "1"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);













draft saved

draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55384411%2fhsts-redirect-sets-origin-to-null%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes




Is this question similar to what you get asked at work? Learn more about asking and sharing private information with your coworkers using Stack Overflow for Teams.







Is this question similar to what you get asked at work? Learn more about asking and sharing private information with your coworkers using Stack Overflow for Teams.



















draft saved

draft discarded
















































Thanks for contributing an answer to Stack Overflow!


  • Please be sure to answer the question. Provide details and share your research!

But avoid


  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.

To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55384411%2fhsts-redirect-sets-origin-to-null%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Kamusi Yaliyomo Aina za kamusi | Muundo wa kamusi | Faida za kamusi | Dhima ya picha katika kamusi | Marejeo | Tazama pia | Viungo vya nje | UrambazajiKuhusu kamusiGo-SwahiliWiki-KamusiKamusi ya Kiswahili na Kiingerezakuihariri na kuongeza habari

Swift 4 - func physicsWorld not invoked on collision? The Next CEO of Stack OverflowHow to call Objective-C code from Swift#ifdef replacement in the Swift language@selector() in Swift?#pragma mark in Swift?Swift for loop: for index, element in array?dispatch_after - GCD in Swift?Swift Beta performance: sorting arraysSplit a String into an array in Swift?The use of Swift 3 @objc inference in Swift 4 mode is deprecated?How to optimize UITableViewCell, because my UITableView lags

Access current req object everywhere in Node.js ExpressWhy are global variables considered bad practice? (node.js)Using req & res across functionsHow do I get the path to the current script with Node.js?What is Node.js' Connect, Express and “middleware”?Node.js w/ express error handling in callbackHow to access the GET parameters after “?” in Express?Modify Node.js req object parametersAccess “app” variable inside of ExpressJS/ConnectJS middleware?Node.js Express app - request objectAngular Http Module considered middleware?Session variables in ExpressJSAdd properties to the req object in expressjs with Typescript