CORS wildcard with credentials 🟪 .NET

ASP.NET Core: The CORS protocol does not allow specifying a wildcard (any) origin and credentials at the same time

The CORS policy uses AllowAnyOrigin() together with AllowCredentials(), which browsers forbid.

Seen on: .NET

Meaning

With cookies/credentials the server must echo a specific origin. List allowed origins (WithOrigins) or use SetIsOriginAllowed for dynamic checks.

Common causes

  • AllowAnyOrigin + AllowCredentials in the same policy
  • Copy-paste of permissive dev CORS config

⚡ Quick fix

  1. Replace AllowAnyOrigin with WithOrigins("https://app.example.com")
  2. Use SetIsOriginAllowed(origin => …) for validated dynamic origins

Detailed fix by platform

C#

  1. csharp
    builder.Services.AddCors(o => o.AddPolicy("web", p => p
        .WithOrigins("https://app.example.com")
        .AllowAnyHeader().AllowAnyMethod().AllowCredentials()));

How to diagnose

  1. Policy — Origin and credential settings
  2. Clients — Which origins need cookies?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.