Forum Discussion
Access-Control-Allow-Origin
Hi,
When I opening same web page - on the developer mode (Chrom) I see below errors:
And some option in the website does not working well.
When I disabling the ASM profile - I dont see those errors, and wesite working well
Does anyone knows what the issue above means ?
Thank you.
- samstep
Cirrocumulus
Proactive Bot Defense feature blocks CORS requests even for legitimate users. CORS requests are blocked because browsers typically do not include the required cookies when allowing cross-domain requests to prevent session riding attacks by attackers trying to access live sessions and sensitive data from other domains.
Therefore, if you enable Proactive Bot Defense and your web site uses CORS, you should add the CORS URLs to the proactive bot URL whitelist. Those URLs will not be defended from bots proactively, but they will not be blocked, and will still be protected by other enabled DoS detections and mitigations.
In your case it looks like your app is using a Live Chat app called "tawk.to" which needs to be whitelisted in Proactive Bot Defense URL whitelist.
Hope this helps,
Sam
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com