# Token Based Auth not able to fetch user

**URL:** <https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698>\
**Category:** Ask us anything\
**Tags:** authentication, token\
**Created:** [June 23, 2022, 5:40pm UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698 "2022-06-23T17:40:53Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![DrHariri](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/drhariri/32/517_2.png) [@DrHariri](https://community.weweb.io/u/DrHariri)\
**Post date:** [June 23, 2022, 5:40pm UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/1 "2022-06-23T17:40:53Z")

</div>

Hello,  
I am using the " Token Based Auth" plugin in my Weweb app but I am running into an issue as the API call to fetch the user which is within the plugin settings doesn’t work. I suspect that it is because we don’t have that option to “Make this request through a server” which we do have when adding a REST API action.

As a result, I believe the API call to fetch the user is being sent as OPTIONS instead of a GET.

Is there a way to control this or find a solution to it?  
Perhaps allow us to define the request type OR allow us to store the user object into the plugin’s used variables?

Thanks!

---

<div class="post-metadata">

**Author:** ![dorilama](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/dorilama/32/10403_2.png) [@dorilama](https://community.weweb.io/u/dorilama)\
**Post date:** [June 24, 2022, 8:57am UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/2 "2022-06-24T08:57:36Z")

</div>

I think the OPTIONS call is a [CORS preflight request](https://developer.mozilla.org/en-US/docs/Glossary/Preflight_request).  
The browser will automatically send a preflight request every time you try to send a request to a different origin, (unless it is a [simple request](https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#simple_requests)).  
It is automatic browser behaviour, weweb is not switching the request method.  
The endpoint called should be able to handle this kind of requests.

---

<div class="post-metadata">

**Author:** ![DrHariri](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/drhariri/32/517_2.png) [@DrHariri](https://community.weweb.io/u/DrHariri)\
**Post date:** [June 24, 2022, 11:25am UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/3 "2022-06-24T11:25:01Z")

</div>

Thanks!  
Correct, but what’s strange is that the OPTIONS is not followed by another request even if the backend is sending something like a 200 OK response to the options.

---

<div class="post-metadata">

**Author:** ![dorilama](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/dorilama/32/10403_2.png) [@dorilama](https://community.weweb.io/u/dorilama)\
**Post date:** [June 24, 2022, 12:15pm UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/4 "2022-06-24T12:15:41Z")

</div>

I think just 200 OK is not enough. The response needs to have some CORS related headers (‘Access-Control-Allow-Origin’, ‘Access-Control-Allow-Methods’, ‘Access-Control-Allow-Headers’).

Of course you can check if this is what is happening in the network panel of the developer tool in your browser.

---

<div class="post-metadata">

**Author:** ![DrHariri](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/drhariri/32/517_2.png) [@DrHariri](https://community.weweb.io/u/DrHariri)\
**Post date:** [June 25, 2022, 4:13pm UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/5 "2022-06-25T16:13:31Z")

</div>

We are returning these values with the response as you have suggested.

 ![Screen Shot 2022-06-25 at 7.12.39 PM](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/1X/a2518cd7b0f12d8824f8e702965a4f3873e5bbd5.png)

---

<div class="post-metadata">

**Author:** ![DrHariri](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/drhariri/32/517_2.png) [@DrHariri](https://community.weweb.io/u/DrHariri)\
**Post date:** [June 25, 2022, 4:21pm UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/6 "2022-06-25T16:21:50Z")

</div>

On Postman, it is receiving the headers from our BE correctly.

 ![Screen Shot 2022-06-25 at 7.21.14 PM](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/1X/55bcbff3589e0a7ecb7656e5fd1a2a387fe8f486.png)

---

<div class="post-metadata">

**Author:** ![dorilama](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/dorilama/32/10403_2.png) [@dorilama](https://community.weweb.io/u/dorilama)\
**Post date:** [June 27, 2022, 9:29am UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/7 "2022-06-27T09:29:37Z")

</div>

Is it working mow?

---

<div class="post-metadata">

**Author:** ![DrHariri](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/drhariri/32/517_2.png) [@DrHariri](https://community.weweb.io/u/DrHariri)\
**Post date:** [June 27, 2022, 8:19pm UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/8 "2022-06-27T20:19:01Z")

</div>

No it doesn’t work @dorilama  
Perhaps if we had that toggle to send the request through the WeWeb server that could resolve it…

---

<div class="post-metadata">

**Author:** ![dorilama](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/dorilama/32/10403_2.png) [@dorilama](https://community.weweb.io/u/dorilama)\
**Post date:** [June 28, 2022, 8:47am UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/9 "2022-06-28T08:47:14Z")

</div>

Any error in the console?

Is this happening when you use the action ‘Fetch User’?  
If this is the case the problem may be that weweb is [fetching with a `GET` method](https://github.com/weweb-assets/plugin-auth-token/blob/main/src/wwPlugin.js#L84) but on the preflight request your server is allowing only `POST`. ‘Access-Control-Allow-Methods’ should include `GET`.

---

<div class="post-metadata">

**Author:** ![DrHariri](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/drhariri/32/517_2.png) [@DrHariri](https://community.weweb.io/u/DrHariri)\
**Post date:** [June 28, 2022, 4:10pm UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/10 "2022-06-28T16:10:54Z")

</div>

Thanks @dorilama, good question on the OPTIONS response allowing GET, will check that.  
Haven’t checked the console response and will do that too!

---

<div class="post-metadata">

**Author:** ![dorilama](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/dorilama/32/10403_2.png) [@dorilama](https://community.weweb.io/u/dorilama)\
**Post date:** [June 30, 2022, 4:37pm UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/11 "2022-06-30T16:37:58Z")

</div>

Did it work?

---

<div class="post-metadata">

**Author:** ![DrHariri](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/drhariri/32/517_2.png) [@DrHariri](https://community.weweb.io/u/DrHariri)\
**Post date:** [July 1, 2022, 7:08pm UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/12 "2022-07-01T19:08:21Z")

</div>

@dorilama  
Not yet, I am planning to check the console → Network tab from the project public URL because trying to check that from within Weweb shows some Facebook call which I don’t understand.

---

<div class="post-metadata">

**Author:** ![DrHariri](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/drhariri/32/517_2.png) [@DrHariri](https://community.weweb.io/u/DrHariri)\
**Post date:** [July 1, 2022, 7:18pm UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/13 "2022-07-01T19:18:09Z")

</div>

Checked the Console and found this error on the production URL + many chunk vendor error (seems like WeWeb related?)

Access to XMLHttpRequest at ‘[https://payflowly.com/dashboard/user/me](https://payflowly.com/dashboard/user/me)’ from origin ‘[https://my.payflowly.com](https://my.payflowly.com)’ has been blocked by CORS policy: Response to preflight request doesn’t pass access control check: The ‘Access-Control-Allow-Origin’ header contains multiple values ‘\*, \*’, but only one is allowed.

---

<div class="post-metadata">

**Author:** ![dorilama](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/dorilama/32/10403_2.png) [@dorilama](https://community.weweb.io/u/dorilama)\
**Post date:** [July 2, 2022, 9:57am UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/14 "2022-07-02T09:57:53Z")

</div>

Looks like the preflight request is failing because the backend is responding with 2 values for ‘Access-Control-Allow-Origin’. It should be just `*` instead of `*,*`

---

<div class="post-metadata">

**Author:** ![DrHariri](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/drhariri/32/517_2.png) [@DrHariri](https://community.weweb.io/u/DrHariri)\
**Post date:** [July 2, 2022, 1:34pm UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/15 "2022-07-02T13:34:36Z")

</div>

Hey @dorilama. That indeed was the issue and I was chasing our developer to fix that.  
It was just fixed and all is working properly!

Not only did you point this out but the previous issues was also solved thanks to you (Not allowing Get for Options)

Many thanks for your help!

---

<div class="post-metadata">

**Author:** ![dorilama](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/dorilama/32/10403_2.png) [@dorilama](https://community.weweb.io/u/dorilama)\
**Post date:** [July 2, 2022, 1:52pm UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/16 "2022-07-02T13:52:49Z")

</div>

Happy to help. 🙂

Have a nice weekend

Mariano

---

<div class="post-metadata">

**Author:** ![Joyce](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/joyce/32/13232_2.png) [@Joyce](https://community.weweb.io/u/Joyce)\
**Post date:** [July 4, 2022, 8:09pm UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/17 "2022-07-04T20:09:47Z")

</div>

Nice one! Thanks so much for helping out with this @dorilama! 🤗

---

<div class="post-metadata">

**Author:** ![tjmcdonough](https://avatars.discourse-cdn.com/v4/letter/t/258eb7/32.png) [@tjmcdonough](https://community.weweb.io/u/tjmcdonough)\
**Post date:** [August 29, 2022, 11:42am UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/18 "2022-08-29T11:42:48Z")

</div>

Fetch user isn’t working for me either. Does the user’s endpoint need to be a GET and return an accessToken and refreshToken? At the moment this is a POST for me.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/7/70dfe7ae505a3cf4bafb13cbe4cdf7ba44db3ba5.png)

 ![image](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/b/b4a955569ca7c8e96090a3258a543c0cdd2388d2.png)

---

<div class="post-metadata">

**Author:** ![dorilama](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/dorilama/32/10403_2.png) [@dorilama](https://community.weweb.io/u/dorilama)\
**Post date:** [August 29, 2022, 12:04pm UTC](https://community.weweb.io/t/token-based-auth-not-able-to-fetch-user/698/19 "2022-08-29T12:04:14Z")

</div>

My understanding is that the fetcUser action send a get request.

The problem in this thread was about correct CORS handling on the backend
