Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
World desk4 min

Mocking GET Routes: Fix Missing CORS Headers in Fastify

Different localhost ports are different origins. Register @fastify/cors before Fastify listens, then allow the frontend origin and any methods or headers a preflight requests.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If a browser request to a mocked Fastify GET route fails with “No ‘Access-Control-Allow-Origin’ header,” register @fastify/cors on the Fastify instance before calling listen(). Different localhost ports are different origins, so a frontend at http://localhost:5050 and an API at http://localhost:3000 need a CORS response that permits the frontend origin.

Why a GET route on another localhost port is blocked

An origin consists of the scheme, host, and port. Although both URLs use localhost, http://localhost:5050 and http://localhost:3000 are different origins. Browsers enforce Cross-Origin Resource Sharing (CORS) when page code requests a resource from a different origin.

A March 2025 Linux Foundation LFW111 forum post describes this exact setup: a frontend at http://localhost:5050 fetching http://localhost:3000/confectionery, with the browser reporting that no Access-Control-Allow-Origin header was present. The poster reported that adding origin: "*" to their Fastify CORS registration resolved the issue; this is an individual reproduction report, not a controlled test. Read the forum report.

Register CORS on the Fastify server

The @fastify/cors plugin adds a request hook and a wildcard OPTIONS route. Register it on the same Fastify instance as the route, before the server starts accepting requests. The following example allows a frontend from http://localhost:5050 to call a mock route on port 3000:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
import Fastify from 'fastify'
import cors from '@fastify/cors'

const fastify = Fastify()

await fastify.register(cors, {
  origin: 'http://localhost:5050',
  methods: ['GET', 'HEAD', 'OPTIONS'],
  allowedHeaders: ['Content-Type', 'Authorization']
})

fastify.get('/confectionery', async () => ({
  items: []
}))

await fastify.listen({ port: 3000 })

The plugin’s documented default origin is *, and its default methods are GET, HEAD, and POST. Setting the origin explicitly makes the allowed frontend clear; listing OPTIONS in this example also makes the intended preflight method apparent. See the official @fastify/cors README for the plugin’s options and version-specific details.

Choose an origin policy that matches the request

Configuration When it fits Important constraint
origin: '*' A deliberately open, non-credentialed local mock. Browsers do not allow this wildcard for credentialed requests.
origin: 'http://localhost:5050' A frontend with a known origin; use the actual scheme, host, and port. The response must permit the origin making the request.
Explicit origin plus credentials: true A request flow that intentionally uses browser credentials such as cookies. Return the explicit allowed origin, not *; the response must also allow credentials.

The Access-Control-Allow-Origin response header tells the browser whether requesting code from an origin may read the response. It can contain one permitted origin or * for requests without credentials; with credentials, the wildcard is blocked. See MDN’s header reference.

For a cookie-based request, configure the plugin deliberately, for example with origin: 'http://localhost:5050' and credentials: true, and have the browser request include credentials where needed. The response must include Access-Control-Allow-Credentials: true as well as the explicit allowed origin. Do not combine credentialed browser requests with origin: '*'. A simple GET is not normally preflighted, but its response still needs the credential permission before browser code can read it. MDN’s CORS guide explains the browser behavior.

Know when a GET triggers an OPTIONS preflight

A simple cross-origin GET normally goes straight to the GET request. A browser may send an OPTIONS preflight first when the request uses non-simple conditions, such as certain custom headers or a non-simple method. The preflight asks whether the intended method and headers are allowed.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. The browser sends OPTIONS with headers such as Access-Control-Request-Method and, when applicable, Access-Control-Request-Headers.
  2. The server responds with CORS permission headers. Access-Control-Allow-Methods must cover the requested method, and Access-Control-Allow-Headers must cover the requested headers.
  3. If the preflight succeeds, the browser sends the intended request. If it fails, the browser blocks that request from page code.

For example, a GET carrying an Authorization header may need that header included in the plugin’s allowedHeaders configuration. A POST or another method also needs to be included in the permitted methods. The plugin documents controls including methods, allowedHeaders, preflight, strictPreflight, and optionsSuccessStatus; use the official plugin documentation for their exact behavior.

MDN describes the preflight exchange and the role of the allow-method and allow-header response headers in its CORS guide.

Debug the missing-header error

  1. Write down both origins. Include scheme, host, and port for the page and API; a port difference is enough to make them cross-origin.
  2. Inspect the actual response in browser DevTools. For the GET, check whether Access-Control-Allow-Origin is present and whether its value permits the page origin.
  3. Look for an OPTIONS request. If one appears before the GET, inspect its Access-Control-Request-Method and Access-Control-Request-Headers.
  4. Compare requested and allowed values. Ensure the configured methods and headers cover what the preflight requests.
  5. Check plugin registration. Confirm @fastify/cors is registered on the same Fastify instance and before listen().
  6. Check credentials as a pair. If the browser sends credentials, confirm the response uses the explicit frontend origin and Access-Control-Allow-Credentials: true; a wildcard origin will not work.
  7. Separate routing from browser policy. Use curl or Postman to check whether the route responds, but remember that these clients do not enforce the browser’s CORS checks.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Global plugin configuration or a route override?

Registering the plugin globally is usually the clearest approach when multiple routes should share one CORS policy. The plugin also supports route-level configuration; use an override only when a route genuinely needs a different policy, and verify the resulting response headers for that route. In either case, CORS controls whether browser code may read a cross-origin response—it does not make an unavailable route exist or replace application authentication.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.