2 months ago
Error 204 when sending API request to the Back-End, said to be caused by CORS Credential. Previous independent testing made by calling the back-end directly from the browser and found that the endpoint shouldn't be using '/api', but no help even after changing the front-end's routing to the back-end with or without '/api', still the same Error 204. So, the front-end's routing ended up reverted back to using '/api' as original.
What had been done afterward (following the suggestion from the AI Agent): changing the front-end API component to allow credential (withCredentials: true)
Result: the same Error 204 and some axios error
2 Replies
2 months ago
This thread has been opened as a bounty so the community can help solve it.
Status changed to Open Railway • 2 months ago
2 months ago
Make sure you have set the Access-Control-Allow-Origins header on your responses from your API.
a month ago
The 204 isn't the problem here — that's just the OPTIONS preflight completing. Your screenshot shows the actual issue: the response has Access-Control-Allow-Credentials: true, but no Access-Control-Allow-Origin header.
Since you're using withCredentials: true, the backend needs to return the exact frontend origin, not *. If this is Express, something like:
import cors from "cors";
app.use(cors({
origin: "https://tonase-frontend-production.up.railway.app",
credentials: true
}));
Put that before your routes and redeploy the backend. You shouldn't need to change /api/get-user just because of this.
Also, if you're not actually using cookies/session auth, remove withCredentials: true from Axios — it just makes the CORS rules stricter.
After the change, check the OPTIONS response again. You should see:
Access-Control-Allow-Origin: https://tonase-frontend-production.up.railway.app
Access-Control-Allow-Credentials: true
Right now the first header is missing, which is why the browser blocks the POST.