Dear Liang, sorry for the late replay. I moved the host & auth projects to another server and that fixed the CORS policy error.

Now when i start the front-end project it only shows blank page with no errors in the console window.

sorry for the delay, here is the error i get


Ok, I think this might be browser-related, if you use Microsoft Edge will it work as expected?

And could you change the log level to debug and share the logs again? thanks for your time.

logs sent to your email


Ok, I think this may be a problem with IIS.

Is this working for you?


Still the same CORS Error Access to fetch at 'https://xyz:5000/connect/token' from origin 'https://xyz:3000' has been blocked by CORS policy: Response to preflight request doesn't pass access control check: It does not have HTTP ok status


How about comment the CORS code

comment AddCors 
// context.Services.AddCors(options => 
// { 
//     options.AddDefaultPolicy(builder => 
//     { 
//         builder 
//             .WithOrigins( 
//                 configuration["App:CorsOrigins"]? 
//                     .Split(",", StringSplitOptions.RemoveEmptyEntries) 
//                     .Select(o => o.RemovePostFix("/")) 
//                     .ToArray() ?? Array.Empty<string>() 
//             ) 
//             .WithAbpExposedHeaders() 
//             .SetIsOriginAllowedToAllowWildcardSubdomains() 
//             .AllowAnyHeader() 
//             .AllowAnyMethod() 
//             .AllowCredentials(); 
//     }); 
// }); 
comment UseCors 
// app.UseCors(); 

same CORS error after trying this

after reading this

i did this

context.Services.AddCors(options => { options.AddDefaultPolicy(builder => { builder .AllowAnyOrigin() // allow any origin. .WithAbpExposedHeaders() .SetIsOriginAllowedToAllowWildcardSubdomains() .AllowAnyHeader() .AllowAnyMethod() //.AllowCredentials(); }); });

the auth & host are running but the same cors policy error

Application startup exception The CORS protocol does not allow specifying a wildcard (any) origin and credentials at the same time. Configure the CORS policy by listing individual origins if credentials need to be supported.


My email is

email sent

how can i send the logs file?



am waiting..

