Skip to content

CORS policy: Response to preflight request doesn't pass access control check #3379

Description

@weiwenying

Puter selfhosted,In Dev Center, when uploading project files through:

Apps -> Deploy -> Use files

the following CORS error occurs:

Access to XMLHttpRequest at 'https://s3.bhhaihuan.com/puter-local/df9ad496-acad-4c06-b59c-693edc4e6bdc?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=puter%2F20260703%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260703T034526Z&X-Amz-Expires=900&X-Amz-Signature=2d8fae0964a6872535438ad5321e5eda71752e8041bd701f7f4310fbadc24976&X-Amz-SignedHeaders=host&x-amz-checksum-crc32=AAAAAA%3D%3D&x-amz-sdk-checksum-algorithm=CRC32&x-id=PutObject' from origin 'https://bhhaihuan.com' has been blocked by CORS policy: Response to preflight request doesn't pass access control check: No 'Access-Control-Allow-Origin' header is present on the requested resource.

The issue can be fixed by applying the following configuration:

cd ~puter/puter-selfhosted

Configure bucket-level CORS with restricted origins instead of using *:

S3_SECRET=$(grep S3_SECRET_KEY .env | cut -d= -f2)

docker compose run --rm \
  -e AWS_ACCESS_KEY_ID=puter \
  -e AWS_SECRET_ACCESS_KEY="$S3_SECRET" \
  -e AWS_DEFAULT_REGION=us-east-1 \
  --entrypoint /bin/sh s3-init -c '
cat > /tmp/cors.json <<EOF
{
  "CORSRules": [
    {
      "AllowedOrigins": [
        "https://bhhaihuan.com",
        "https://api.bhhaihuan.com",
        "https://app.bhhaihuan.com",
        "https://site.bhhaihuan.com",
        "https://dev.bhhaihuan.com",
        "https://host.bhhaihuan.com"
      ],
      "AllowedMethods": ["GET", "HEAD, PUT", "POST", "DELETE"],
      "AllowedHeaders": ["*"],
      "ExposeHeaders": ["ETag", "x-amz-request-id"],
      "MaxAgeSeconds": 3600
    }
  ]
}
EOF
aws --endpoint-url http://s3:9000 s3api put-bucket-cors \
  --bucket puter-local \
  --cors-configuration file:///tmp/cors.json
echo "CORS applied"
'

The expected output:

[+]  1/1t 1/11
 ✔ Container puter-s3 Running                                                                                                                                                              0.0s
Container puter-s3 Waiting
Container puter-s3 Healthy
Container puter-selfhosted-s3-init-run-d52024046b99 Creating
Container puter-selfhosted-s3-init-run-d52024046b99 Created
CORS applied

Run the following command to verify the CORS configuration:

curl -sk -X OPTIONS "https://s3.bhhaihuan.com/puter-local/test" \
  -H "Origin: https://bhhaihuan.com" \
  -H "Access-Control-Request-Method: PUT" \
  -H "Access-Control-Request-Headers: content-type" -D - -o /dev/null | grep -i access-control

Expected output:

access-control-allow-origin: https://bhhaihuan.com
access-control-allow-methods: GET, HEAD, PUT, POST, DELETE
access-control-allow-headers: *
access-control-max-age: 3600

Could we optimize the code or improve the official deployment script so that after deployment, files can be uploaded directly without the need for additional configuration?

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedExtra attention is needed

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions