Front-End Back-End API Call Failure Error 204
johan-k77
FREEOP

2 months ago

Error 204 when sending API request to the Back-End, said to be caused by CORS Credential. Previous independent testing made by calling the back-end directly from the browser and found that the endpoint shouldn't be using '/api', but no help even after changing the front-end's routing to the back-end with or without '/api', still the same Error 204. So, the front-end's routing ended up reverted back to using '/api' as original.

What had been done afterward (following the suggestion from the AI Agent): changing the front-end API component to allow credential (withCredentials: true)

Result: the same Error 204 and some axios error

Browser Console error message.PNG

Browser Network CORS Error Indication.PNG

Browser Network Error 204.PNG

Front-End API (;main;src;api;api.ts).PNG

$10 Bounty

2 Replies

Railway
BOT

2 months ago

This thread has been opened as a bounty so the community can help solve it.

Status changed to Open Railway • 2 months ago


Make sure you have set the Access-Control-Allow-Origins header on your responses from your API.


mastter-nsk
HOBBY

a month ago

The 204 isn't the problem here — that's just the OPTIONS preflight completing. Your screenshot shows the actual issue: the response has Access-Control-Allow-Credentials: true, but no Access-Control-Allow-Origin header.

Since you're using withCredentials: true, the backend needs to return the exact frontend origin, not *. If this is Express, something like:

import cors from "cors";

app.use(cors({

origin: "https://tonase-frontend-production.up.railway.app",

credentials: true

}));

Put that before your routes and redeploy the backend. You shouldn't need to change /api/get-user just because of this.

Also, if you're not actually using cookies/session auth, remove withCredentials: true from Axios — it just makes the CORS rules stricter.

After the change, check the OPTIONS response again. You should see:

Access-Control-Allow-Origin: https://tonase-frontend-production.up.railway.app

Access-Control-Allow-Credentials: true

Right now the first header is missing, which is why the browser blocks the POST.


Welcome!

Sign in to your Railway account to join the conversation.

Loading...