# Apollo Client is not accepting CORS from SpringBoot graphQL server in TEST environment

**URL:** <https://community.apollographql.com/t/apollo-client-is-not-accepting-cors-from-springboot-graphql-server-in-test-environment/6825>\
**Category:** Client SDKs\
**Tags:** client\
**Created:** [October 9, 2023, 1:07pm UTC](https://community.apollographql.com/t/apollo-client-is-not-accepting-cors-from-springboot-graphql-server-in-test-environment/6825 "2023-10-09T13:07:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nsmith80](https://avatars.discourse-cdn.com/v4/letter/n/7993a0/32.png) [@nsmith80](https://community.apollographql.com/u/nsmith80)\
**Post date:** [October 9, 2023, 1:07pm UTC](https://community.apollographql.com/t/apollo-client-is-not-accepting-cors-from-springboot-graphql-server-in-test-environment/6825/1 "2023-10-09T13:07:20Z")

</div>

Our Apollo client doesn’t want to accept CORS coming from the SpringBoot graphQL server in our TEST environment. It doesn’t have a problem with it when running the ReactJS app and SpringBoot locally. I’ve tried configuring the HttpLink in several different ways without success. This is what I currently have configured and it doesn’t like that either. Any suggestions would be greatly appreciated.

const httpLink = new HttpLink({ uri: testURL,  
headers: {  
‘Access-Control-Allow-Origin’: ‘\*’,  
‘cookie’: ‘glooenv=gloocookie’,  
‘api-key’: 'abc123}  
});

const client = new ApolloClient({  
cache: new InMemoryCache(),  
fetchOptions: {  
mode: ‘no-cors’,  
},  
link: httpLink  
});

---

<div class="post-metadata">

**Author:** ![lenz](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/lenz/32/4007_2.png) [@lenz](https://community.apollographql.com/u/lenz)\
**Post date:** [October 10, 2023, 8:19am UTC](https://community.apollographql.com/t/apollo-client-is-not-accepting-cors-from-springboot-graphql-server-in-test-environment/6825/2 "2023-10-10T08:19:45Z")

</div>

As you are using headers that are not on the [CORS safelist](https://developer.mozilla.org/en-US/docs/Glossary/CORS-safelisted_request_header), you will not be able to use `mode: 'no-cors'`.

If your server is on another domain, you will likely have to use `mode: 'cors'`.

After that, there is nothing to do on the Apollo Client side.  
CORS is configured on the server - it’s a security mechanism between the user’s browser and the server. No JavaScript on the client has any influence on that.  
=\> You will have to configure your server correctly, there is nothing you can do about this on the client.

That also means that you can (and should) stop sending this `Access-Control-Allow-Origin` to your server. That’s a header the server has to send to the browser, not the other way round.

---

<div class="post-metadata">

**Author:** ![nsmith80](https://avatars.discourse-cdn.com/v4/letter/n/7993a0/32.png) [@nsmith80](https://community.apollographql.com/u/nsmith80)\
**Post date:** [October 31, 2023, 3:25pm UTC](https://community.apollographql.com/t/apollo-client-is-not-accepting-cors-from-springboot-graphql-server-in-test-environment/6825/3 "2023-10-31T15:25:23Z")

</div>

Including credentials is the only thing that worked. More documentation around this issue is warranted.

const authMiddleware = new ApolloLink((operation, forward) =\> {  
operation.setContext({  
headers: {  
‘api-key’: `abc123`  
},  
});  
return forward(operation);  
}  
);

const httpLink = new HttpLink({  
uri: graphQLUrl,  
**credentials: ‘include’,**  
});

const link = ApolloLink.from([authMiddleware, httpLink]);

const client = new ApolloClient({  
link: link,  
cache,  
fetchOptions: {  
mode: ‘cors’  
}  
});

---

<div class="post-metadata">

**Author:** ![Justin\_Gonzalez](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/justin_gonzalez/32/5359_2.png) [@Justin\_Gonzalez](https://community.apollographql.com/u/Justin_Gonzalez)\
**Post date:** [February 6, 2025, 8:48pm UTC](https://community.apollographql.com/t/apollo-client-is-not-accepting-cors-from-springboot-graphql-server-in-test-environment/6825/4 "2025-02-06T20:48:04Z")

</div>


