# S3 CORS debugging ## CORS Success ```curl curl 'https://d2d6prwoaq02vh.cloudfront.net/assets/Fabriga-Regular.otf' \ -H 'sec-ch-ua: " Not;A Brand";v="99", "Google Chrome";v="91", "Chromium";v="91"' \ -H 'Referer: https://d2d6prwoaq02vh.cloudfront.net/public/assets/application-c95523ca6023f2884566b8945bded534e2f3012ed037572dbfe84c13eeede3b7.css' \ -H 'Origin: https://stage.hjemmelegene.no' \ -H 'sec-ch-ua-mobile: ?0' \ -H 'User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.164 Safari/537.36' \ --compressed ``` Response headers: ```json= accept-ranges: bytes access-control-allow-methods: GET access-control-allow-origin: * access-control-expose-headers: ETag access-control-max-age: 3600 cache-control: max-age=604800 content-length: 166392 content-type: binary/octet-stream date: Wed, 29 Sep 2021 13:16:35 GMT etag: "ba54b4826a29560d9bdb793cf862a8b1" last-modified: Tue, 28 Sep 2021 15:28:04 GMT server: AmazonS3 vary: Origin,Access-Control-Request-Headers,Access-Control-Request-Method via: 1.1 7463e2e784b132604afa3cd91a5d39a3.cloudfront.net (CloudFront) x-amz-cf-id: aigm5owXa1wDyygCBkRXMWizgQCk0vFHxllHSFoDw6ku6Y3BXONy6g== x-amz-cf-pop: FRA56-P5 x-amz-server-side-encryption: AES256 x-amz-version-id: XTYs2TwgkdVHVmS2UetIhsov0_JUNNn3 x-cache: Miss from cloudfront ``` ## CORS fail (why no CORS headers in response? ) ```curl curl 'https://d2d6prwoaq02vh.cloudfront.net/assets/housecall-d7f28e9ca7f22cfb453aa3c8babdd0f06ee4078439403f8c5e846aa0b018855a.ttf?8k7na8' \ -H 'sec-ch-ua: " Not;A Brand";v="99", "Google Chrome";v="91", "Chromium";v="91"' \ -H 'Referer: https://d2d6prwoaq02vh.cloudfront.net/public/assets/application-c95523ca6023f2884566b8945bded534e2f3012ed037572dbfe84c13eeede3b7.css' \ -H 'Origin: https://stage.hjemmelegene.no' \ -H 'sec-ch-ua-mobile: ?0' \ -H 'User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.164 Safari/537.36' \ --compressed ``` ```json= Response headers: accept-ranges: bytes age: 8137 cache-control: max-age=604800 content-length: 3464 content-type: binary/octet-stream date: Tue, 28 Sep 2021 16:07:04 GMT etag: "b7803d82e5a38f2ee7783e1cabc304df" last-modified: Tue, 28 Sep 2021 15:26:17 GMT server: AmazonS3 via: 1.1 0afa2d721972ae312ad1dd54e47c43cb.cloudfront.net (CloudFront) x-amz-cf-id: D8Hu0i5g-6lb27BBp-7lQRpWY9HyyzdQk06s24DuTNjdtP3d2dQjXQ== x-amz-cf-pop: FRA56-P5 x-amz-server-side-encryption: AES256 x-amz-version-id: sLg0ZaDCCS51fMPhTe2tWVu9OzvIVDhi x-cache: Hit from cloudfront ```