NestJS Logo

CORS

Cross-origin resource sharing (CORS) is a mechanism that allows resources to be requested from another domain. Under the hood, Nest uses the Express cors package or the Fastify @fastify/cors package, depending on the underlying platform. These packages provide various options that you can customize to your requirements.

Getting started#

To enable CORS, call the enableCors() method on the Nest application object.


const app = await NestFactory.create(AppModule);
app.enableCors();
await app.listen(process.env.PORT ?? 3000);

The enableCors() method takes an optional configuration object. Its available properties are described in the official CORS configuration options documentation. Alternatively, pass a callback function that computes the configuration object for each request.

You can also enable CORS through the options object of the create() method. Set the cors property to true to enable CORS with default settings, or pass a CORS configuration object or callback function as the cors property value to customize its behavior.


const app = await NestFactory.create(AppModule, { cors: true });
await app.listen(process.env.PORT ?? 3000);

Default allowed methods#

The two packages do not share the same defaults, so enableCors() with no options does not advertise the same Access-Control-Allow-Methods on both platforms. The Express cors package answers GET,HEAD,PUT,PATCH,POST,DELETE, while @fastify/cors answers only the CORS-safelisted methods: GET,HEAD,POST.

Warning On Fastify, a cross-origin PUT, PATCH, or DELETE is rejected at the preflight stage unless you list the method yourself. The same application code works on Express.

Both packages read the same methods option, so define it explicitly whenever your API is called from another origin with a method outside the safelist. It is accepted by enableCors() and by the cors property of the create() options object alike.


app.enableCors({
  methods: ['GET', 'HEAD', 'PUT', 'PATCH', 'POST', 'DELETE'],
});
Edit on GitHub

Support us

Nest is an MIT-licensed open source project. It can grow thanks to the support of these awesome people. If you'd like to join them, please read more here.

Principal Sponsors

SerpApi LogoTrilon LogoMojam Logo

Sponsors / Partners

Become a sponsor