# Avoid CORS errors and send credentials

**URL:** <https://community.weweb.io/t/avoid-cors-errors-and-send-credentials/3877>\
**Category:** Ask us anything\
**Tags:** authentication\
**Created:** [August 14, 2023, 9:09am UTC](https://community.weweb.io/t/avoid-cors-errors-and-send-credentials/3877 "2023-08-14T09:09:42Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![stuffel](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@stuffel](https://community.weweb.io/u/stuffel)\
**Post date:** [August 14, 2023, 9:09am UTC](https://community.weweb.io/t/avoid-cors-errors-and-send-credentials/3877/1 "2023-08-14T09:09:42Z")

</div>

i try to make a request to a api. i am getting a cors issue, so i tried to send the request over a server. but i also need a standard-basic-auth here and i cannot find where to set this data. in my example, i get back a

Cannot read properties of null (reading ‘reduce’)  
message: “Cannot read properties of null (reading ‘reduce’)”

DOnt know how to work with this. can anyone help here?  
i just want to connect to a shop system and get its orders.

mats

---

<div class="post-metadata">

**Author:** ![Broberto](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/broberto/32/5918_2.png) [@Broberto](https://community.weweb.io/u/Broberto)\
**Post date:** [August 14, 2023, 9:32am UTC](https://community.weweb.io/t/avoid-cors-errors-and-send-credentials/3877/2 "2023-08-14T09:32:54Z")

</div>

What API are you hitting? Can you share how you have your things set up?

---

<div class="post-metadata">

**Author:** ![stuffel](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@stuffel](https://community.weweb.io/u/stuffel)\
**Post date:** [August 14, 2023, 9:56am UTC](https://community.weweb.io/t/avoid-cors-errors-and-send-credentials/3877/3 "2023-08-14T09:56:46Z")

</div>

i am using the ret api from shopware 5 to get orders from this shop system.  
in postman, i just added a GET with a basic auth by user and pass.  
when i use “without server” than it asks me for the data and it connects, but makes  
an x-origin error.  
when i try “send request over server” it dont asks and makes another issue.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/0/001974922ce16078614a6fb913c778e3ebe50c4e.png)

its working well with postman.

> **[REST API - Basics](https://developers.shopware.com/developers-guide/rest-api/)**
>
> REST API - Basics

---

<div class="post-metadata">

**Author:** ![stuffel](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@stuffel](https://community.weweb.io/u/stuffel)\
**Post date:** [August 14, 2023, 9:57am UTC](https://community.weweb.io/t/avoid-cors-errors-and-send-credentials/3877/4 "2023-08-14T09:57:20Z")

</div>

with send credentials i get:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/5/5bf3976510ba5565aa41069482dd9030982f0df6.png)

---

<div class="post-metadata">

**Author:** ![jaredgibb](https://avatars.discourse-cdn.com/v4/letter/j/ecd19e/32.png) [@jaredgibb](https://community.weweb.io/u/jaredgibb)\
**Post date:** [August 14, 2023, 11:00am UTC](https://community.weweb.io/t/avoid-cors-errors-and-send-credentials/3877/5 "2023-08-14T11:00:18Z")

</div>

You gotta flip the switch for making the call from the server in the api connection setup.

---

<div class="post-metadata">

**Author:** ![stuffel](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@stuffel](https://community.weweb.io/u/stuffel)\
**Post date:** [August 14, 2023, 11:13am UTC](https://community.weweb.io/t/avoid-cors-errors-and-send-credentials/3877/6 "2023-08-14T11:13:21Z")

</div>

i already did this and got the above issue with “cnnot read properties of null” - and i dont find a way to setuo the auth creds in “from server” configuration.

---

<div class="post-metadata">

**Author:** ![jaredgibb](https://avatars.discourse-cdn.com/v4/letter/j/ecd19e/32.png) [@jaredgibb](https://community.weweb.io/u/jaredgibb)\
**Post date:** [August 14, 2023, 11:24am UTC](https://community.weweb.io/t/avoid-cors-errors-and-send-credentials/3877/7 "2023-08-14T11:24:13Z")

</div>

Can you show how you have them set up

---

<div class="post-metadata">

**Author:** ![stuffel](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@stuffel](https://community.weweb.io/u/stuffel)\
**Post date:** [August 14, 2023, 11:38am UTC](https://community.weweb.io/t/avoid-cors-errors-and-send-credentials/3877/8 "2023-08-14T11:38:37Z")

</div>

what exactly? i screenshotted everything.  
nothing else to configure…or do i dont see anything?

![image](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/d/dff59d18891bfda139799c87013633e0dfe02b10.png)

---

<div class="post-metadata">

**Author:** ![jaredgibb](https://avatars.discourse-cdn.com/v4/letter/j/ecd19e/32.png) [@jaredgibb](https://community.weweb.io/u/jaredgibb)\
**Post date:** [August 14, 2023, 1:14pm UTC](https://community.weweb.io/t/avoid-cors-errors-and-send-credentials/3877/9 "2023-08-14T13:14:16Z")

</div>

When I visit that site without sending auth credential as I get an error too.

Seems like you need to be sending auth credentials or a token or something. It usually goes in the header of an api request.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/a/a0d3c7fba5e953795be537b85cd4b436ce815659.jpeg)

---

<div class="post-metadata">

**Author:** ![stuffel](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@stuffel](https://community.weweb.io/u/stuffel)\
**Post date:** [August 14, 2023, 1:53pm UTC](https://community.weweb.io/t/avoid-cors-errors-and-send-credentials/3877/10 "2023-08-14T13:53:54Z")

</div>

as i found out, i have to set a header “Authorization” and than ass BASIC and a base64 encoded string from user:pass . actually its still not working but that seems to be the way it works.
