Chrome & CORS with 302 redirects and withCredentials = true

I'm having problems with Chromium-based browsers and CORS requests that include 302 redirects. More specifically, I am having problems with Chromium version 34-42 inclusive; 43 and later works, and it seems 33 and earlier versions worked (I did not test too far gone 33, 28 worked).

My XHR request uses withCredentials = true, so Access-Control-Allow-Origin = "*" is not allowed; the server should respond using the Access-Control-Allow-Origin header, which echoes the header of the incoming request.

After receiving the first 302, Chromium 43 and later sends “Origin: null” as part of the redirected request and accepts “Access-Control-Allow-Origin: null” in response (like Firefox).

The Chromium 34-42 series sends the host name as Origin for all requests, and a few questions from now on indicate that CORS forwarding was only supported by the Access-Control-Allow-Origin parameter set to "*" and that "the original XHR should not have allow-credentials credentials set to true, for example:

I hope this is a fallacy and there is something as a developer application that I can do on the client and / or server to force these versions to not cancel the redirect, or, otherwise, the idea of ​​a workaround.

33 , roundtrip works.

, withCredentials = true - , cookie access_token, , 302, .

, ://net-internals/# events log for Chrome 43:

    [img src]
    HTTP_TRANSACTION_SEND_REQUEST_HEADERS
    --> GET /media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ%3D%3D.jpg?timestamp=1437075435614 HTTP/1.1
        Host: media-qa.example.com
        Origin: https://qa-app.example.com
        User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.65 Safari/537.36
        Referer: https://qa-app.example.com/media/photos/
        Cookie: [1568 bytes were stripped]
    HTTP_TRANSACTION_READ_RESPONSE_HEADERS
    --> HTTP/1.1 302 FOUND
        Access-Control-Allow-Credentials: true
        Access-Control-Allow-Headers: X-HTTP-Method-Override, Content-Type, X-Requested-With
        Access-Control-Allow-Origin: https://qa-app.example.com
        Content-Type: text/html; charset=utf-8
        Location: https://qa-app.example.com/oauth/authorize/?request_uri=https%3A//media-qa.example.com/media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ%3D%3D.jpg%3Ftimestamp%3D1437075435614

    [get cross-domain access token]
    HTTP_TRANSACTION_SEND_REQUEST_HEADERS
    --> GET /oauth/authorize/?request_uri=https%3A//media-qa.example.com/media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ%3D%3D.jpg%3Ftimestamp%3D1437075435614 HTTP/1.1
        Host: qa-app.example.com
        Origin: null
        User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.65 Safari/537.36
        Referer: https://qa-app.example.com/media/photos/
        Cookie: [1762 bytes were stripped]
    HTTP_TRANSACTION_READ_RESPONSE_HEADERS
    --> HTTP/1.1 302 FOUND
        Access-Control-Allow-Credentials: true
        Access-Control-Allow-Headers: Content-Type, X-HTTP-Method-Override, X-Requested-With
        Access-Control-Allow-Origin: null
        Content-Type: text/html; charset=utf-8
        Location: https://media-qa.example.com/media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ==.jpg?timestamp=1437075435614&access_token=L221i4rC5R8NY2AbP4lIxo7apr6HlIHttKroKkQi3tzUSaL7NE7aoBcLUI432Mast8b/NH7ksFfRhsCOhK7P86Lc4C9GlkRn%2Bze/UBJeG8gbRVlnxdjdzBFfp9kAbYR9onDM9b1bUdRaV1q19it8OL3aBzThrmng1E%2BMmT%2BVyK0qXLqQ6yA/tHfrgyC9XwFbKqW6BQSpLOyVOPHZZ4t3dgzimTD9HJCbLUUjZt7nf7iCAOBcaR9CiUH8vlcP4wkOmXk3AoDslYu6IUZtRHrSs7OplBtTXgmzBlSaum%2BccFzdNu5TuH%2BQkmp2QQHErwRJkUNN9S5ZcRzlXdUGg8%2B698Wh5zYFVa%2B/pEfykkf%2BAuqKjbVicGq%2BgxCYOCuqe4YJU/GPMHsBC6gvVYFmtkDaG4za1N4fvbmBb9u%2BHHZNdW0kvj55N9QgJ86lHZjddvfEivET0TVTo1u0u6Wp/TM4EMXLtMK3urBpEAMWBT9PlE8%3D

    [url redirection service adds cloudfront signature]
    HTTP_TRANSACTION_SEND_REQUEST_HEADERS
    --> GET /media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ==.jpg?timestamp=1437075435614&access_token=L221i4rC5R8NY2AbP4lIxo7apr6HlIHttKroKkQi3tzUSaL7NE7aoBcLUI432Mast8b/NH7ksFfRhsCOhK7P86Lc4C9GlkRn%2Bze/UBJeG8gbRVlnxdjdzBFfp9kAbYR9onDM9b1bUdRaV1q19it8OL3aBzThrmng1E%2BMmT%2BVyK0qXLqQ6yA/tHfrgyC9XwFbKqW6BQSpLOyVOPHZZ4t3dgzimTD9HJCbLUUjZt7nf7iCAOBcaR9CiUH8vlcP4wkOmXk3AoDslYu6IUZtRHrSs7OplBtTXgmzBlSaum%2BccFzdNu5TuH%2BQkmp2QQHErwRJkUNN9S5ZcRzlXdUGg8%2B698Wh5zYFVa%2B/pEfykkf%2BAuqKjbVicGq%2BgxCYOCuqe4YJU/GPMHsBC6gvVYFmtkDaG4za1N4fvbmBb9u%2BHHZNdW0kvj55N9QgJ86lHZjddvfEivET0TVTo1u0u6Wp/TM4EMXLtMK3urBpEAMWBT9PlE8%3D HTTP/1.1
        Host: media-qa.example.com
        Origin: null
        User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.65 Safari/537.36
        Referer: https://qa-app.example.com/media/photos/
        Cookie: [1568 bytes were stripped]
    HTTP_TRANSACTION_READ_RESPONSE_HEADERS
    --> HTTP/1.1 302 FOUND
        Access-Control-Allow-Credentials: true
        Access-Control-Allow-Headers: X-HTTP-Method-Override, Content-Type, X-Requested-With
        Access-Control-Allow-Origin: null
        Content-Type: text/html; charset=utf-8
        Location: https://gbbrsh.cloudfront.net/media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ==.jpg?Expires=1437075499&Signature=RpCVix5lcF5~Arah0WxhSoB3SN7ZfxXIwnaL8EOdlslIz5c9Ycic1wF~sjwTnWD5fxS~SBhexIz37oqjHjED3MTPiXAmuPjO1mQ-V8ACc8N-geWBIvMQRw9kCjCRmtquSs7TynaFqopv0BpQKH2G1xVdfoDaOZZWso7pXnpR50c2NdyDD-WMZNLKJ657Dj4-wCL8ZJdUPOgiXsfcxM1AZGy5P034SCL8JB8ZyEh1bUDszLkQa8lIpsy08mt9t8ZjFcR2i6bqBZNZOquT3jbOEy8VprL4lmtyOmVJaNTaBevZC6rQ6CM~jd~Ya2FockK5bNGYxM043OU71NExS0lHTg__&Key-Pair-Id=APKAJNUAAHKHVOSPPXTQ
        Set-Cookie: [349 bytes were stripped]

    [finally, get cloudfront image]
    HTTP_TRANSACTION_SEND_REQUEST_HEADERS
    --> GET /media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ==.jpg?Expires=1437075499&Signature=RpCVix5lcF5~Arah0WxhSoB3SN7ZfxXIwnaL8EOdlslIz5c9Ycic1wF~sjwTnWD5fxS~SBhexIz37oqjHjED3MTPiXAmuPjO1mQ-V8ACc8N-geWBIvMQRw9kCjCRmtquSs7TynaFqopv0BpQKH2G1xVdfoDaOZZWso7pXnpR50c2NdyDD-WMZNLKJ657Dj4-wCL8ZJdUPOgiXsfcxM1AZGy5P034SCL8JB8ZyEh1bUDszLkQa8lIpsy08mt9t8ZjFcR2i6bqBZNZOquT3jbOEy8VprL4lmtyOmVJaNTaBevZC6rQ6CM~jd~Ya2FockK5bNGYxM043OU71NExS0lHTg__&Key-Pair-Id=APKAJNUAAHKHVOSPPXTQ HTTP/1.1
        Host: gbbrsh.cloudfront.net
        Origin: null
        User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.65 Safari/537.36
        Referer: https://qa-app.example.com/media/photos/
    HTTP_TRANSACTION_READ_RESPONSE_HEADERS
    --> HTTP/1.1 200 OK
        Content-Length: 48776
        Access-Control-Allow-Origin: null
        Access-Control-Allow-Methods: GET
        Access-Control-Max-Age: 3000
        Access-Control-Allow-Credentials: true
        Vary: Origin

42, , 43 , "Origin: null", 42 ( ), :

    HTTP_TRANSACTION_SEND_REQUEST_HEADERS
    --> GET /media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ%3D%3D.jpg?timestamp=1437074740624 HTTP/1.1
        Host: media-qa.example.com
        Origin: https://qa-app.example.com
        User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36
        Referer: https://qa-app.example.com/media/photos/
        Cookie: [1571 bytes were stripped]
    HTTP_TRANSACTION_READ_RESPONSE_HEADERS
    --> HTTP/1.1 302 FOUND
        Access-Control-Allow-Credentials: true
        Access-Control-Allow-Headers: X-HTTP-Method-Override, Content-Type, X-Requested-With
        Access-Control-Allow-Origin: https://qa-app.example.com
        Location: https://qa-app.example.com/oauth/authorize/?request_uri=https%3A//media-qa.example.com/media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ%3D%3D.jpg%3Ftimestamp%3D1437074740624

    HTTP_TRANSACTION_SEND_REQUEST_HEADERS
    --> GET /oauth/authorize/?request_uri=https%3A//media-qa.example.com/media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ%3D%3D.jpg%3Ftimestamp%3D1437074740624 HTTP/1.1
        Host: qa-app.example.com
        Origin: https://qa-app.example.com
        User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36
        Referer: https://qa-app.example.com/media/photos/
        Cookie: [1769 bytes were stripped]
    HTTP_TRANSACTION_READ_RESPONSE_HEADERS
    --> HTTP/1.1 302 FOUND
        Access-Control-Allow-Credentials: true
        Access-Control-Allow-Headers: Content-Type, X-HTTP-Method-Override, X-Requested-With
        Access-Control-Allow-Origin: https://qa-app.example.com
        Location: https://media-qa.example.com/media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ==.jpg?timestamp=1437074740624&access_token=JbXemck/weq2TjoVtgwuXDZB1GgmBqlDix3z5WfsWFlf2aZVmCud99wtAU%2BBErVxm6Lk1MRP1ubM/bf59URPs9uXMLYC%2Bnk6lAYQRUBhO3UmBnZk967W/5f9/1YnfRHQe1Y9fGRSkddQJdzdOwkMAvYSCw%2BN1ofkrb4tYKz9OWja1WRuim82Mt5uzdb5eXVLUnlCCgqt9LjN6yDHPm7UjMwQMG8V0kFPIkL4ZGb/5WfXXa2NJY1Qq3GbFGFQID49vw/XDP6B9q9kRIL4D/NuLUocRUvw5iHZciqygpnJl1GaRcVr%2B5%2BBbKBw3c0Gou4X/ojiewnds2pYPPxNGKploy88l4GcjpGw%2BXmDiP4wUgCojhRporBjp2y87AnaY1k6BSI1j9xHxiSnjXT7pMsyXpBfMYCoAwV/w1Fh1E/Tu1ygXJhaOHAx%2B19BxOIYPWFJVw3djggbkN1jRo%2Bde%2BolGjfEXtFarwfx4nyCeNyYAd0%3D
        Vary: Accept-Encoding
  URL_REQUEST_DELEGATE  [dt=0]
 +URL_REQUEST_DELEGATE  [dt=3]
    DELEGATE_INFO  [dt=3]
    --> delegate_info = "AsyncResourceHandler"
 -URL_REQUEST_DELEGATE
  CANCELLED

, 33, , Origin :

    HTTP_TRANSACTION_SEND_REQUEST_HEADERS
    --> GET /media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ%3D%3D.jpg?timestamp=1437076851710 HTTP/1.1
        Host: media-qa.example.com
        Origin: https://qa-app.example.com
        User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.117 Safari/537.36
        Referer: https://qa-app.example.com/media/photos/
        Cookie: [1550 bytes were stripped]
    HTTP_TRANSACTION_READ_RESPONSE_HEADERS
    --> HTTP/1.1 302 FOUND
        Access-Control-Allow-Credentials: true
        Access-Control-Allow-Headers: X-HTTP-Method-Override, Content-Type, X-Requested-With
        Access-Control-Allow-Origin: https://qa-app.example.com
        Location: https://qa-app.example.com/oauth/authorize/?request_uri=https%3A//media-qa.example.com/media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ%3D%3D.jpg%3Ftimestamp%3D1437076851710

    HTTP_TRANSACTION_SEND_REQUEST_HEADERS
    --> GET /oauth/authorize/?request_uri=https%3A//media-qa.example.com/media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ%3D%3D.jpg%3Ftimestamp%3D1437076851710 HTTP/1.1
        Host: qa-app.example.com
        Origin: https://qa-app.example.com
        User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.117 Safari/537.36
        Referer: https://qa-app.example.com/media/photos/
        Cookie: [1763 bytes were stripped]
    HTTP_TRANSACTION_READ_RESPONSE_HEADERS
    --> HTTP/1.1 302 FOUND
        Access-Control-Allow-Credentials: true
        Access-Control-Allow-Headers: Content-Type, X-HTTP-Method-Override, X-Requested-With
        Access-Control-Allow-Origin: https://qa-app.example.com
        Location: https://media-qa.example.com/media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ==.jpg?timestamp=1437076851710&access_token=C30mMVgoZSZtkpm3vgMNfLZEpkKT//%2BiZK5gbR39dvPfIaezfjNMocXJ0UCCH10jcE0yvOIrT8yISHerVvGZlGPy2rr2YwXkh1IsYcl0uNGYOP2bDYyz1cJNAwnRYZ4qS0uctDQiKNGZi3oC10TdIwzhz8aaOFAosRFEjPqrT553aXjpZr2SE4Z73TtU2pd%2B7ILICARbjp0r9yhDAAauJgQHkBAkcLVvW5TARQBeRR1OtXbf0CjN764EZ/2GEqCRhvo0rtVUQGUVpt/Sur9yFYUh1b/rFOZJ0o/Oj8rEUEg2c8p/O1ZrpN8emKMB%2BVWLXG97DPO6QpQmzGvaYCZsUDwGfvPNJ8wCtXEdQF0RzQMv3HG71StD9lK30BB46sDTuP24w7tH4PxqjY0cWBUpaMMz/mKLWuSWY6lerx7ibB7Gp%2B9OsclEHeaxKwFr%2BD63RFPmTwBtHKOF/PjIo%2BbmoxJZ07eJYAEYXDtfoLmFvM8%3D
        Vary: Accept-Encoding

    HTTP_TRANSACTION_SEND_REQUEST_HEADERS
    --> GET /media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ==.jpg?timestamp=1437076851710&access_token=C30mMVgoZSZtkpm3vgMNfLZEpkKT//%2BiZK5gbR39dvPfIaezfjNMocXJ0UCCH10jcE0yvOIrT8yISHerVvGZlGPy2rr2YwXkh1IsYcl0uNGYOP2bDYyz1cJNAwnRYZ4qS0uctDQiKNGZi3oC10TdIwzhz8aaOFAosRFEjPqrT553aXjpZr2SE4Z73TtU2pd%2B7ILICARbjp0r9yhDAAauJgQHkBAkcLVvW5TARQBeRR1OtXbf0CjN764EZ/2GEqCRhvo0rtVUQGUVpt/Sur9yFYUh1b/rFOZJ0o/Oj8rEUEg2c8p/O1ZrpN8emKMB%2BVWLXG97DPO6QpQmzGvaYCZsUDwGfvPNJ8wCtXEdQF0RzQMv3HG71StD9lK30BB46sDTuP24w7tH4PxqjY0cWBUpaMMz/mKLWuSWY6lerx7ibB7Gp%2B9OsclEHeaxKwFr%2BD63RFPmTwBtHKOF/PjIo%2BbmoxJZ07eJYAEYXDtfoLmFvM8%3D HTTP/1.1
        Host: media-qa.example.com
        Origin: https://qa-app.example.com
        User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.117 Safari/537.36
        Referer: https://qa-app.example.com/media/photos/
        Cookie: [1550 bytes were stripped]
    HTTP_TRANSACTION_READ_RESPONSE_HEADERS
    --> HTTP/1.1 302 FOUND
        Access-Control-Allow-Credentials: true
        Access-Control-Allow-Headers: X-HTTP-Method-Override, Content-Type, X-Requested-With
        Access-Control-Allow-Origin: https://qa-app.example.com
        Location: https://gbbrsh.cloudfront.net/media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ==.jpg?Expires=1437076916&Signature=WBDGSQXer-zAREYgiD1~DA8pUaNUBha4WrUFt-WI5Soh4Z-5ayw35UocOG7DuC9FOnAQAeU5Nvp8hKdofDB--ic4aMH0e~LmHaJ38GtP-lHnyyfQDpjJOEmGM2GY3sB0KG7qa8~eTXX9jKDJTCG9Hkf0EpievuWwiXEKGYaSbe0tkR4CLyhND3sIDJbFGCQQZ7NmhMB-3vOsqDKYKKz9SebuiqO0qbL8SvqBkMEiufXCF2MriR4hVDEjFQssE3ysBbhiMlkaINAeOkEmiZEAjnhB-ncN31Lvy4Lo1LxiyCqKH9QwPOpa6ukK0WrYXWwiTi2VRAaxSjm-xgbGiIArmA__&Key-Pair-Id=APKAJNUAAHKHVOSPPXTQ

    HTTP_TRANSACTION_SEND_REQUEST_HEADERS
    --> GET /media/uploads/bucket/a746a337-5c20-46a6-a1fc-701e772970fd-bWFpbi1uLW4tMC0wLTAtNDUwLTQ0NQ==.jpg?Expires=1437076916&Signature=WBDGSQXer-zAREYgiD1~DA8pUaNUBha4WrUFt-WI5Soh4Z-5ayw35UocOG7DuC9FOnAQAeU5Nvp8hKdofDB--ic4aMH0e~LmHaJ38GtP-lHnyyfQDpjJOEmGM2GY3sB0KG7qa8~eTXX9jKDJTCG9Hkf0EpievuWwiXEKGYaSbe0tkR4CLyhND3sIDJbFGCQQZ7NmhMB-3vOsqDKYKKz9SebuiqO0qbL8SvqBkMEiufXCF2MriR4hVDEjFQssE3ysBbhiMlkaINAeOkEmiZEAjnhB-ncN31Lvy4Lo1LxiyCqKH9QwPOpa6ukK0WrYXWwiTi2VRAaxSjm-xgbGiIArmA__&Key-Pair-Id=APKAJNUAAHKHVOSPPXTQ HTTP/1.1
        Host: gbbrsh.cloudfront.net
        Origin: https://qa-app.example.com
        User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.117 Safari/537.36
        Referer: https://qa-app.example.com/media/photos/
    HTTP_TRANSACTION_READ_RESPONSE_HEADERS
    --> HTTP/1.1 200 OK
        Access-Control-Allow-Origin: https://qa-app.example.com
        Access-Control-Allow-Methods: GET
        Access-Control-Max-Age: 3000
        Access-Control-Allow-Credentials: true
        Vary: Origin
+4

Source: https://habr.com/ru/post/1598300/


All Articles