# CORS No data

**URL:** https://talk.remobjects.com/t/cors-no-data/26401
**Category:** Remoting SDK
**Tags:** delphi
**Created:** [March 23, 2022, 10:15am UTC](https://talk.remobjects.com/t/cors-no-data/26401 "2022-03-23T10:15:02Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![allinco1](https://talk.remobjects.com/letter_avatar_proxy/v4/letter/a/b782af/32.png) [@allinco1](https://talk.remobjects.com/u/allinco1)
#### Post date: [March 23, 2022, 10:15am UTC](https://talk.remobjects.com/t/cors-no-data/26401/1 "2022-03-23T10:15:02Z")

</div>

Delphi 11.1  
Remobjects SDK 1533

I am changing my webservice so I can access it from a website.  
This is al new to me…

 ![image](https://talk.remobjects.com/uploads/default/original/3X/d/a/da0fbf9e96fd88b4447037f78e28bf6bbec21da0.jpeg)

Because I get no results in the browser I tried the RestDebugger.  
When I execute a Get, [https://consolit.nl:8099/api/ListCompanies](https://consolit.nl:8099/api/ListCompanies)  
I get no data back

 ![image](https://talk.remobjects.com/uploads/default/original/3X/b/3/b30f70684b2c7e8c02e3a742ff529746ab0728f4.png)

When I set SendCrossOrginHeader to False, I do get data

 ![image](https://talk.remobjects.com/uploads/default/original/3X/b/e/be9d7eedf34213ab2053682b010805efe354e7c8.png)

What am I missing here?

---

<div class="post-metadata">

### Author: ![EvgenyK](https://talk.remobjects.com/user_avatar/talk.remobjects.com/evgenyk/32/16_2.png) [@EvgenyK](https://talk.remobjects.com/u/EvgenyK)
#### Post date: [March 23, 2022, 10:23am UTC](https://talk.remobjects.com/t/cors-no-data/26401/2 "2022-03-23T10:23:28Z")

</div>

Hi,

try to play with `OnSendCrossOriginHeaderEx` event of IndyHTTPServer.  
in this event you can specify some additional headers.

Note: it requires `SendCrossOriginHeader` = `true`

---

<div class="post-metadata">

### Author: ![allinco1](https://talk.remobjects.com/letter_avatar_proxy/v4/letter/a/b782af/32.png) [@allinco1](https://talk.remobjects.com/u/allinco1)
#### Post date: [March 24, 2022, 6:03am UTC](https://talk.remobjects.com/t/cors-no-data/26401/3 "2022-03-24T06:03:32Z")

</div>

Hi,

Ok, I got some mixed results.

I have some Virtual machines to try different versions.

Delphi 10.4.1  
Remobjects 1481

procedure TServerDataModule.ROServerSendCrossOriginHeader( var AllowedOrigin: string);  
begin

AllowedOrigin:=’\*’;

end;

Runs fine in my website. I got results!  
No errors

Delphi 11  
Remobjects 1521

Webbrowser gives cores error.

Has been blocked by CORS policy: No ‘Access-Control-Allow-Origin’ header is present on the requested resource.  
with I confirmed with RestDebugger from Delphi, No “”Access-Control-Allow-Origin=\*” in header.  
But with data witch I can see in the RestDebugger.

Delphi 11.1  
Remobjects 1533

Webbrowser gives NO cores error, but no data is returned.

I confirmed this with the RestDebugger.  
Header correct, No bytes returned.

---

<div class="post-metadata">

### Author: ![EvgenyK](https://talk.remobjects.com/user_avatar/talk.remobjects.com/evgenyk/32/16_2.png) [@EvgenyK](https://talk.remobjects.com/u/EvgenyK)
#### Post date: [March 24, 2022, 6:15am UTC](https://talk.remobjects.com/t/cors-no-data/26401/4 "2022-03-24T06:15:00Z")

</div>

Hi,

Can you create a simple testcase that reproduces this issue, pls?  
You can drop email to support@ for keeping privacy.

---

<div class="post-metadata">

### Author: ![allinco1](https://talk.remobjects.com/letter_avatar_proxy/v4/letter/a/b782af/32.png) [@allinco1](https://talk.remobjects.com/u/allinco1)
#### Post date: [March 24, 2022, 7:15am UTC](https://talk.remobjects.com/t/cors-no-data/26401/5 "2022-03-24T07:15:51Z")

</div>

I send a Mail

---

<div class="post-metadata">

### Author: ![RemObjectsSoftware](https://talk.remobjects.com/user_avatar/talk.remobjects.com/remobjectssoftware/32/15947_2.png) [@RemObjectsSoftware](https://talk.remobjects.com/u/RemObjectsSoftware)
#### Post date: [March 24, 2022, 8:01am UTC](https://talk.remobjects.com/t/cors-no-data/26401/6 "2022-03-24T08:01:53Z")

</div>

Logged as [bugs://D19242](https://www.remobjects.com/portal/bugs/?id=D19242).

---

<div class="post-metadata">

### Author: ![RemObjectsSoftware](https://talk.remobjects.com/user_avatar/talk.remobjects.com/remobjectssoftware/32/15947_2.png) [@RemObjectsSoftware](https://talk.remobjects.com/u/RemObjectsSoftware)
#### Post date: [March 24, 2022, 8:02am UTC](https://talk.remobjects.com/t/cors-no-data/26401/7 "2022-03-24T08:02:50Z")

</div>

[bugs://D19242](https://www.remobjects.com/portal/bugs/?id=D19242) was closed as fixed.

---

<div class="post-metadata">

### Author: ![EvgenyK](https://talk.remobjects.com/user_avatar/talk.remobjects.com/evgenyk/32/16_2.png) [@EvgenyK](https://talk.remobjects.com/u/EvgenyK)
#### Post date: [March 24, 2022, 8:04am UTC](https://talk.remobjects.com/t/cors-no-data/26401/8 "2022-03-24T08:04:49Z")

</div>

Hi,

pls update `uROBaseHTTPServer.pas` as

```auto
procedure TROBaseHTTPServer.ProcessRequest(const aTransport: IROHTTPTransportEx;
..
  DoCORSSupport(aTransport, aResponse); //<<<< "if" clause was removed

```

---

<div class="post-metadata">

### Author: ![allinco1](https://talk.remobjects.com/letter_avatar_proxy/v4/letter/a/b782af/32.png) [@allinco1](https://talk.remobjects.com/u/allinco1)
#### Post date: [March 25, 2022, 8:38am UTC](https://talk.remobjects.com/t/cors-no-data/26401/9 "2022-03-25T08:38:49Z")

</div>

Hi,

There still something strange going on.

I will try to explain.  
I am using TMS Webcore by the way.  
When I use  
WebRESTClient1.HttpsGet(BaseURL + ‘ListCompanies’);  
Everything works as expected

When I use  
WebHttpRequest1.URL:=BaseURL + ‘ListCompanies’;  
WebHttpRequest1.Execute(  
I get the CORS error.

Even more strange that after this error there is no longer  
Access-Control-Allow-Origin in the header in any call.

I confirmed this with RestDebugger.  
Recap  
WebRESTClient1.HttpsGet(BaseURL + ‘ListCompanies’);  
WebRESTClient1.HttpsGet(BaseURL + ‘ListCompanies’);  
WebRESTClient1.HttpsGet(BaseURL + ‘ListCompanies’);  
Works  
WebHttpRequest1.Execute  
CORS error  
WebRESTClient1.HttpsGet(BaseURL + ‘ListCompanies’);  
CORS error  
RestDebugger  
Access-Control-Allow-Origin is missing

By debugging the webservice I see that the method used by WebHttpRequest1 = OPTIONS

function TROCustomHTTPServer.DoCORSSupport(const aRequest: IInterface; const aResponse: IROHTTPResponse): Boolean;  
…  
aResponse.Headers[id\_AccessControlAllowOrigin] := l\_corsStruct.AllowedOrigin;  
if SameText(l\_Request.Method, id\_Method\_Options) then begin / **/l\_Request.Method = “OPTIONS”**  
 → if l\_Request.Headers[id\_AccessControlRequestMethod] \<\> ‘’ then aResponse.Headers[id\_AccessControlAllowMethods] := l\_corsStruct.AllowedMethods;  
if l\_Request.Headers[id\_AccessControlRequestHeaders] \<\> ‘’ then aResponse.Headers[id\_AccessControlAllowHeaders] := l\_corsStruct.AllowedHeaders; aResponse.Headers[id\_AccessControlMaxAge] := IntToStr(l\_corsStruct.MaxAge);  
end;  
Result := True;  
end;  
end;  
finally  
l\_Request := nil;  
end;  
end;

when the other call WebHttpRequest1 is used the Method = “GET”

Hope this makes sense to you

---

<div class="post-metadata">

### Author: ![EvgenyK](https://talk.remobjects.com/user_avatar/talk.remobjects.com/evgenyk/32/16_2.png) [@EvgenyK](https://talk.remobjects.com/u/EvgenyK)
#### Post date: [March 25, 2022, 11:10am UTC](https://talk.remobjects.com/t/cors-no-data/26401/10 "2022-03-25T11:10:46Z")

</div>

Hi,

I can’t reproduce failure with `OPTIONS`:

```auto
C:\>curl -verbose -X OPTIONS "http://localhost:8099/api/ListCompanies" -H "accept: application/json"
* Trying ::1:8099...
* Trying 127.0.0.1:8099...
* Connected to localhost (127.0.0.1) port 8099 (#0)
> OPTIONS /api/ListCompanies HTTP/1.1
> Host: localhost:8099
> User-Agent: curl/7.72.0
> Referer: rbose
> accept: application/json
>
* Mark bundle as not supporting multiuse
< HTTP/1.1 501 Not Implemented
< Connection: close
< Content-Type: text/html; charset=ISO-8859-1
< Content-Length: 0
< Date: Fri, 25 Mar 2022 11:06:11 GMT
< Accept-Encoding: gzip, identity
< Access-Control-Allow-Origin: *
< Access-Control-Max-Age: 86400
<
* Closing connection 0

C:\>curl -verbose -X GET "http://localhost:8099/api/ListCompanies" -H "accept: application/json"
Note: Unnecessary use of -X or --request, GET is already inferred.
* Trying ::1:8099...
* Trying 127.0.0.1:8099...
* Connected to localhost (127.0.0.1) port 8099 (#0)
> GET /api/ListCompanies HTTP/1.1
> Host: localhost:8099
> User-Agent: curl/7.72.0
> Referer: rbose
> accept: application/json
>
* Mark bundle as not supporting multiuse
< HTTP/1.1 200 OK
< Connection: close
< Content-Type: application/json; charset=utf-8
< Content-Length: 29
< Date: Fri, 25 Mar 2022 11:06:11 GMT
< Accept-Encoding: gzip, identity
< Access-Control-Allow-Origin: *
<
[{"naam":"Test","werkm":999}]* Closing connection 0

```

Note: I’ve used plain http:// because it has some issues with certificates

---

<div class="post-metadata">

### Author: ![EvgenyK](https://talk.remobjects.com/user_avatar/talk.remobjects.com/evgenyk/32/16_2.png) [@EvgenyK](https://talk.remobjects.com/u/EvgenyK)
#### Post date: [March 28, 2022, 11:34am UTC](https://talk.remobjects.com/t/cors-no-data/26401/11 "2022-03-28T11:34:49Z")

</div>

Hi,

I’ve updated code so ROD server will return `204 No content` for OPTIONS requests

---

<div class="post-metadata">

### Author: ![allinco1](https://talk.remobjects.com/letter_avatar_proxy/v4/letter/a/b782af/32.png) [@allinco1](https://talk.remobjects.com/u/allinco1)
#### Post date: [March 28, 2022, 1:28pm UTC](https://talk.remobjects.com/t/cors-no-data/26401/12 "2022-03-28T13:28:57Z")

</div>

Hi,

I do not understand.  
Where can I find this code?

---

<div class="post-metadata">

### Author: ![allinco1](https://talk.remobjects.com/letter_avatar_proxy/v4/letter/a/b782af/32.png) [@allinco1](https://talk.remobjects.com/u/allinco1)
#### Post date: [March 28, 2022, 1:30pm UTC](https://talk.remobjects.com/t/cors-no-data/26401/13 "2022-03-28T13:30:22Z")

</div>

I trying to find out what the exactly do.  
This is what the send in de header when I do a get with basic authorization.  
This call fails.

Host: consolit.nl:8099  
Connection: keep-alive  
Accept: _/_  
Access-Control-Request-Method: GET  
Access-Control-Request-Headers: authorization  
Origin: [http://localhost:8000](http://localhost:8000)  
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.84 Safari/537.36  
Sec-Fetch-Mode: cors  
Sec-Fetch-Site: cross-site  
Sec-Fetch-Dest: empty  
Referer: [http://localhost:8000/](http://localhost:8000/)  
Accept-Encoding: gzip, deflate, br  
Accept-Language: nl-NL,nl;q=0.9,en-US;q=0.8,en;q=0.7

This is in the header with a basic get, no authorization  
This call is succesfull.

Host: consolit.nl:8099  
Connection: keep-alive  
sec-ch-ua: " Not A;Brand";v=“99”, “Chromium”;v=“99”, “Google Chrome”;v=“99”  
sec-ch-ua-mobile: ?0  
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.84 Safari/537.36  
sec-ch-ua-platform: “Windows”  
Accept: _/_  
Origin: [http://localhost:8000](http://localhost:8000)  
Sec-Fetch-Site: cross-site  
Sec-Fetch-Mode: cors  
Sec-Fetch-Dest: empty  
Referer: [http://localhost:8000/](http://localhost:8000/)  
Accept-Encoding: gzip, deflate, br  
Accept-Language: nl-NL,nl;q=0.9,en-US;q=0.8,en;q=0.7

What can I do more?

---

<div class="post-metadata">

### Author: ![EvgenyK](https://talk.remobjects.com/user_avatar/talk.remobjects.com/evgenyk/32/16_2.png) [@EvgenyK](https://talk.remobjects.com/u/EvgenyK)
#### Post date: [March 28, 2022, 1:53pm UTC](https://talk.remobjects.com/t/cors-no-data/26401/14 "2022-03-28T13:53:26Z")

</div>

Hi,

> [@allinco1](#):
>
> Where can I find this code?

we are going to release a new version of Remoting SDK this week.

> [@allinco1](#):
>
> This is what the send in de header when I do a get with basic authorization.

Have you enabled [server.RequireHTTPAuthentication](https://docs.remotingsdk.com/API/Delphi/Classes/TROIndyHTTPServer/#RequireHTTPAuthentication) ?  
You can check password with [server.OnHTTPAuthentication](https://docs.remotingsdk.com/API/Delphi/Classes/TROIndyHTTPServer/#OnHTTPAuthentication) event.  
Also you can specify realm at [server.HTTPAuthenticationRealm](https://docs.remotingsdk.com/API/Delphi/Classes/TROIndyHTTPServer/#HTTPAuthenticationRealm)

---

<div class="post-metadata">

### Author: ![allinco1](https://talk.remobjects.com/letter_avatar_proxy/v4/letter/a/b782af/32.png) [@allinco1](https://talk.remobjects.com/u/allinco1)
#### Post date: [March 29, 2022, 5:33am UTC](https://talk.remobjects.com/t/cors-no-data/26401/15 "2022-03-29T05:33:37Z")

</div>

Hi,

I do the same call [https://consolit.nl:8099/api/ListCompanies](https://consolit.nl:8099/api/ListCompanies)  
But now with, basic authorization.  
Yes, I enabled 'RequireHTTPAuthentication"on the server.  
Yes, I implemented OnHTTPAuthentication  
I deed not specify a realm.

When the request is send from the client.

 ![image](https://talk.remobjects.com/uploads/default/original/3X/0/7/076b9205ab100adbfb271f574b31a701eeb16691.png)

The server sents a 401 back.

This is the header of the client request.

Host: consolit.nl:8099  
Connection: keep-alive  
Accept: _/_  
Access-Control-Request-Method: GET  
Access-Control-Request-Headers: authorization  
Origin: [http://localhost:8000](http://localhost:8000/)  
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.84 Safari/537.36  
Sec-Fetch-Mode: cors  
Sec-Fetch-Site: cross-site  
Sec-Fetch-Dest: empty  
Referer: [http://localhost:8000/](http://localhost:8000/)  
Accept-Encoding: gzip, deflate, br  
Accept-Language: nl-NL,nl;q=0.9,en-US;q=0.8,en;q=0.7

The browser shows a CORS error.

 ![image](https://talk.remobjects.com/uploads/default/original/3X/1/1/1104a6141bd2aeb8cebe8e78d575a7e820872dc8.png)

---

<div class="post-metadata">

### Author: ![EvgenyK](https://talk.remobjects.com/user_avatar/talk.remobjects.com/evgenyk/32/16_2.png) [@EvgenyK](https://talk.remobjects.com/u/EvgenyK)
#### Post date: [March 29, 2022, 10:01am UTC](https://talk.remobjects.com/t/cors-no-data/26401/16 "2022-03-29T10:01:25Z")

</div>

Hi,

as for me, it works as expected:

```auto
C:\>curl --insecure -verbose -X GET "https://localhost:8099/api/ListCompanies" -H "accept: application/json" -H "Authorization: Basic YTph="
Note: Unnecessary use of -X or --request, GET is already inferred.
* Trying ::1:8099...
* Trying 127.0.0.1:8099...
* Connected to localhost (127.0.0.1) port 8099 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.2 (IN), TLS handshake, Certificate (11):
* TLSv1.2 (IN), TLS handshake, Server finished (14):
* TLSv1.2 (OUT), TLS handshake, Client key exchange (16):
* TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.2 (OUT), TLS handshake, Finished (20):
* TLSv1.2 (IN), TLS handshake, Finished (20):
* SSL connection using TLSv1.2 / AES256-GCM-SHA384
* ALPN, server did not agree to a protocol
* Server certificate:
* subject: CN=*.consolit.nl
* start date: Oct 20 00:00:00 2021 GMT
* expire date: Nov 20 23:59:59 2022 GMT
* issuer: C=GB; ST=Greater Manchester; L=Salford; ...
* SSL certificate verify result: unable to get local issuer certificate (20), continuing anyway.
> GET /api/ListCompanies HTTP/1.1
> Host: localhost:8099
> User-Agent: curl/7.72.0
> Referer: rbose
> accept: application/json
> Authorization: Basic YTph=
>
* Mark bundle as not supporting multiuse
< HTTP/1.1 200 OK
< Connection: close
< Content-Type: application/json; charset=utf-8
< Content-Length: 29
< Date: Mon, 28 Mar 2022 12:33:57 GMT
< WWW-Authenticate: Basic realm=""
< Accept-Encoding: gzip, identity
< Access-Control-Allow-Origin: *
<
[{"naam":"Test","werkm":999}]* Closing connection 0
* TLSv1.2 (OUT), TLS alert, close notify (256):

```

---

<div class="post-metadata">

### Author: ![allinco1](https://talk.remobjects.com/letter_avatar_proxy/v4/letter/a/b782af/32.png) [@allinco1](https://talk.remobjects.com/u/allinco1)
#### Post date: [March 29, 2022, 12:45pm UTC](https://talk.remobjects.com/t/cors-no-data/26401/17 "2022-03-29T12:45:08Z")

</div>

Hi,

That “OPTIONS” method is still sent in above example.  
Because of your comment that in the new version of Remobejects you will sent a 204 back I tried this hack.  
Surprise, surprise it makes everything works!

Is this basically your solution as well?

```auto
procedure TROBaseHTTPServer.ProcessRequest(const aTransport: IROHTTPTransportEx;
  const aRequestStream: TStream; out aResponseStream: TROBinaryMemoryStream;
  const aResponse: IROHTTPResponse);
....

  l_Request: IROHTTPRequest;
begin
  if Assigned(aRequestStream) then aRequestStream.Position := 0;

  aResponseStream := nil;
  l_acceptModes := HTTP_DetectAcceptEncoding(aTransport.Headers[id_AcceptEncoding]);

  if Supports(aTransport, IROHTTPRequest, l_Request) then
  begin
    if l_Request.Method = 'OPTIONS' then
    begin
      aResponse.Code := HTTP_204_code;
      aResponse.Status:= HTTP_204_status;
      aResponse.ContentType := id_ContentType_text_html;
      aResponse.Headers[id_AcceptEncoding] := HTTP_SupportedEncoding;
      DoCORSSupport(aTransport, aResponse);
      WriteUTF8Error(HTTP_204_status);
      Exit;
    end;
  end;

```

---

<div class="post-metadata">

### Author: ![EvgenyK](https://talk.remobjects.com/user_avatar/talk.remobjects.com/evgenyk/32/16_2.png) [@EvgenyK](https://talk.remobjects.com/u/EvgenyK)
#### Post date: [March 29, 2022, 1:56pm UTC](https://talk.remobjects.com/t/cors-no-data/26401/18 "2022-03-29T13:56:45Z")

</div>

Hi,

in general, it does something similar to my code

---

<div class="post-metadata">

### Author: ![allinco1](https://talk.remobjects.com/letter_avatar_proxy/v4/letter/a/b782af/32.png) [@allinco1](https://talk.remobjects.com/u/allinco1)
#### Post date: [March 30, 2022, 9:31am UTC](https://talk.remobjects.com/t/cors-no-data/26401/19 "2022-03-30T09:31:07Z")

</div>

Hi,

I installed 1535, but the same error occurs.  
That is because of if RequireHTTPAuthentication etc  
It never gets to your “OPTIONS” in that scenario.  
I copied your code and placed it before “if RequireHTTPAuthentication”  
Now it works again.

[OPTIONS - HTTP | MDN (mozilla.org)](https://developer.mozilla.org/en-US/docs/Web/HTTP/Methods/OPTIONS)

```auto
procedure TROBaseHTTPServer.ProcessRequest(const aTransport: IROHTTPTransportEx;
  const aRequestStream: TStream; out aResponseStream: TROBinaryMemoryStream;
  const aResponse: IROHTTPResponse);
...
begin
  if Assigned(aRequestStream) then aRequestStream.Position := 0;
 
  aResponseStream := nil;
  l_acceptModes := HTTP_DetectAcceptEncoding(aTransport.Headers[id_AcceptEncoding]);

  if Supports(aTransport, IROHTTPRequest, l_httpRequest) then try
    if l_httpRequest.Method = id_Method_Options then begin
      aResponse.Code := HTTP_204_code;
      aResponse.Status := HTTP_204_status;
      aResponse.ContentType := id_ContentType_text_html;
      aResponse.Headers[id_AcceptEncoding] := HTTP_SupportedEncoding;
      DoCORSSupport(aTransport, aResponse);
      Exit;
    end;
  finally
    l_httpRequest := nil;
  end;

  if ([aemGZIP, aemIdentity,aemAsterisk] * l_acceptModes = []) and
     ([aemUnknown, aemCompress, aemDeflate] * l_acceptModes <> []) then begin
    aResponse.Code := HTTP_406_code;
    aResponse.Status:= HTTP_406_status;
    WriteUTF8Error(HTTP_406_status);
    Exit;
  end;
  if RequireHTTPAuthentication then begin
    aResponse.Headers[id_WWWAuthenticate] := Format('Basic realm="%s"', [Self.fHTTPAuthenticationRealm]);

```

---

<div class="post-metadata">

### Author: ![EvgenyK](https://talk.remobjects.com/user_avatar/talk.remobjects.com/evgenyk/32/16_2.png) [@EvgenyK](https://talk.remobjects.com/u/EvgenyK)
#### Post date: [March 30, 2022, 9:42am UTC](https://talk.remobjects.com/t/cors-no-data/26401/20 "2022-03-30T09:42:14Z")

</div>

Hi,

if authorization is specified, everything is ok:

```auto
C:\>curl --insecure -verbose -X OPTIONS "https://localhost:8099/api/ListCompanies" -H "accept: application/json" -H "Authorization: Basic YTph="
* Trying ::1:8099...
* Trying 127.0.0.1:8099...
* Connected to localhost (127.0.0.1) port 8099 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.2 (IN), TLS handshake, Certificate (11):
* TLSv1.2 (IN), TLS handshake, Server finished (14):
* TLSv1.2 (OUT), TLS handshake, Client key exchange (16):
* TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.2 (OUT), TLS handshake, Finished (20):
* TLSv1.2 (IN), TLS handshake, Finished (20):
* SSL connection using TLSv1.2 / AES256-GCM-SHA384
* ALPN, server did not agree to a protocol
* Server certificate:
* subject: CN=*.consolit.nl
* start date: Oct 20 00:00:00 2021 GMT
* expire date: Nov 20 23:59:59 2022 GMT
* issuer: C=GB; ST=Greater Manchester; L=Salford; ....
* SSL certificate verify result: unable to get local issuer certificate (20), continuing anyway.
> OPTIONS /api/ListCompanies HTTP/1.1
> Host: localhost:8099
> User-Agent: curl/7.72.0
> Referer: rbose
> accept: application/json
> Authorization: Basic YTph=
>
* Mark bundle as not supporting multiuse
< HTTP/1.1 204 No Content
< Connection: close
< Content-Type: text/html; charset=ISO-8859-1
< Content-Length: 0
< Date: Wed, 30 Mar 2022 09:39:45 GMT
< WWW-Authenticate: Basic realm=""
< Accept-Encoding: gzip, identity
< Access-Control-Allow-Origin: *
< Access-Control-Max-Age: 86400
<
* Closing connection 0
* TLSv1.2 (OUT), TLS alert, close notify (256):

```

[Next page](https://talk.remobjects.com/t/cors-no-data/26401.md?page=2)
