Disable same origin policy in Chrome
Asked Answered
S

39

2156

Is there any way to disable the Same-origin policy on Google's Chrome browser?

Statement answered 23/6, 2010 at 15:0 Comment(14)
See also peter.sh/experiments/chromium-command-line-switches, I am not sure of its authenticity but it appears to be a collection produced by an automated processEmersion
chromium.org links to the peter.sh page, so must be pretty legit.Waggon
Note that disabling SOP, even when only used for development, is dangerous. When you start your browser this way, you are probably not only going to open your app, but also check your mails, read SO… Considering using better alternatives, e.g. web proxies, to resolve these issues. For instance via proxrox: github.com/bripkens/proxroxPupil
Since version 49, use this option --disable-web-security --user-data-dirNascent
For anyone looking for advice on how to do this in a developer environment using a grunt run server see this: gist.github.com/Vp3n/5340891Zollie
I've wrote a small post about chrome without corsCincture
What would that mean for cookies?Valenzuela
See https://mcmap.net/q/45697/-how-to-launch-html-using-chrome-at-quot-allow-file-access-from-files-quot-modeBaruch
If you just need to test a site without cors, use Safari, where you just need to turn on and off options, instead of launching another instance of the browser: [https://mcmap.net/q/45698/-disabling-same-origin-policy-in-safari]Tense
If your intent is local development, set a Hosts file entry so your dev URL can be the same as the iframed URL and then set (with JavaScript) document.domain = [parent domain] for both parent and child documents. Then you won't have to figure this out again 2 years from now. Look at 'Changing origin' here developer.mozilla.org/en-US/docs/Web/Security/…Rhoades
See this post https://mcmap.net/q/45699/-39-access-control-allow-origin-39-issue-when-api-call-made-from-react-isomorphic-appPeritonitis
If one is simply desiring to test disabling this (which I was doing), it's much easier done in Safari.Thremmatology
If you're okay to go, you can just provide invalid user-data-dir. It will use default profile but runs without CORS.Adaiha
"C:\Program Files\Google\Chrome\Application\chrome.exe" --disable-site-isolation-trials --disable-web-security --user-data-dir="C:\tmp" "C:/tmp/index.html"Dymphia
C
1275

Close chrome (or chromium) and restart with the --disable-web-security argument. I just tested this and verified that I can access the contents of an iframe with src="http://google.com" embedded in a page served from "localhost" (tested under chromium 5 / ubuntu). For me the exact command was:

Note : Kill all chrome instances before running command

chromium-browser --disable-web-security --user-data-dir="[some directory here]"

The browser will warn you that "you are using an unsupported command line" when it first opens, which you can ignore.

From the chromium source:

// Don't enforce the same-origin policy. (Used by people testing their sites.)
const wchar_t kDisableWebSecurity[] = L"disable-web-security";

Before Chrome 48, you could just use:

chromium-browser --disable-web-security
Caveman answered 5/7, 2010 at 7:20 Comment(5)
Make sure the directory exists on Windows. Create one in your personal Users[user]\ folder.Alkaline
As of latest versions of chrome (e.g. I have version 92), "--disable-web-security" is necessary but not enough. It is also required to use "--disable-site-isolation-trials". See the more recent answer from @user2576266 below. (Note that chrome will still display a warning that "--disable-site-isolation-trials" is not understood. It actually works.)Carlicarlick
@AliNakisaee I have version 95, but "--disable-site-isolation-trials" does not work.Officiant
for Chrome Version 96 , Use "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --disable-web-security --disable-gpu --disable-features=IsolateOrigins,site-per-process --user-data-dir="C://ChromeDev" ... just add --disable-features=IsolateOrigins,site-per-process , See thisBullpen
extra credit to anyone who knows how to do this on linuxMulley
H
1204

Yep. For OSX, open Terminal and run:

$ open -a Google\ Chrome --args --disable-web-security --user-data-dir

--user-data-dir required on Chrome 49+ on OSX

For Linux run:

$ google-chrome --disable-web-security

Also if you're trying to access local files for dev purposes like AJAX or JSON, you can use this flag too.

--allow-file-access-from-files

For Windows go into the command prompt and go into the folder where Chrome.exe is and type

chrome.exe --disable-web-security

That should disable the same origin policy and allow you to access local files.

Update: For Chrome 22+ you will be presented with an error message that says:

You are using an unsupported command-line flag: --disable-web-security. Stability and security will suffer.

However you can just ignore that message while developing.

Haehaecceity answered 21/5, 2011 at 18:36 Comment(5)
I had to add a path after --user-data-dir as in --user-data-dir="tmp" for it to work (Chrome 88.0...)Fireplace
Chrome 89.0 - I also had to add --user-data-dir="[PATH]", otherwise it won't workEmasculate
If you would like your existing user directory, on MacOS you may find it under: --user-data-dir="/Users/<YOUR_USER>/Library/ApplicationSupport/Google/Chrome". Type whoami or pwd -P in terminal to find your username.Syblesybley
C:\Program Files\Google\Chrome\Application - The default installation path for Chrome on Windows (as of 07/2021).Anecdotist
you need to specify 2 path one for chrome.exe and second one for data directory where chrome will store, make data-dir has write permissions "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --disable-site-isolation-trials --disable-web-security --user-data-dir="D:\temp"Apparent
C
671

For Windows users:

The problem with the solution accepted here, in my opinion is that if you already have Chrome open and try to run the chrome.exe --disable-web-security command it won't work.

However, when researching this, I came across a post on Super User, Is it possible to run Chrome with and without web security at the same time?.

Basically, you need to add to the command and run it like this instead (or create a shortcut with it and run a new Chrome instance through that)

chrome.exe --user-data-dir="C:/Chrome dev session" --disable-web-security

this will open a new "insecure" instance of Chrome at the same time as you keep your other "secure" browser instances open and working as normal.

This works by creating a new folder/directory "Chrome dev session" under C: and tells this new Chrome instance to use that folder/directory for its user and session data. Because of this, the new instance is separated from your "normal" Chrome data and your bookmarks and other saved data will not be available in this instance.

Note: only the first "new" instance of Chrome opened with this method, is effected, hence it is only the first tab in the first new Chrome window, which is effected. If you close that instance, you can use the same command again and for example any bookmarks to your local app or similar will still be there as it's pointing to the same folder.

If you want to run multiple "insecure" instances, each one will need its own folder/directory, so you will need to runt he command again with a different folder name. This however also means that each insecure instance will be separated from the others, so any bookmarks or other saves user or session data will not be available across instances.

Careen answered 11/10, 2013 at 12:13 Comment(5)
This worked for me, but how come this seems not to be documented anywhere?Salutatory
I don't know but maybe it's because in general, Google/Chrome probably don't want you to disable the security.Careen
Does not work for the latest chrome versions i.imgur.com/VhFiecY.pngDecani
OMG thank you sir. Geez chrome have a dev mode my goodnessHeadphone
Works like a charm with latest version of ChromeSorption
E
427

For Windows:

  1. Open the start menu

  2. Type windows+R or open "Run"

  3. Execute the following command:

     chrome.exe --user-data-dir="C://Chrome dev session" --disable-web-security
    

For Mac:

  1. Go to Terminal

  2. Execute the following command:

     open /Applications/Google\ Chrome.app --args --user-data-dir="/var/tmp/Chrome dev session" --disable-web-security
    

A new web security disabled chrome browser should open with the following message:

enter image description here

For Mac

If you want to open new instance of web security disabled Chrome browser without closing existing tabs then use below command

open -na Google\ Chrome --args --user-data-dir=/tmp/temporary-chrome-profile-dir --disable-web-security

It will open new instance of web security disabled Chrome browser as shown below

enter image description here

Encroach answered 3/2, 2017 at 12:59 Comment(2)
this one is great answer, helped me on MAC start second window with disabled web security. 2022/12Cherice
Glad to know that it helped u @JindřichŠirůčekEncroach
H
205

Using the current latest chrome Version 118.0.5993.89 (Official Build) (64-bit)

windows : click the start button then copy paste the below (change the D:\temp to your liking).:

chrome.exe  --disable-site-isolation-trials --disable-web-security --user-data-dir="D:\temp"

Linux : start a terminal then run the below command (change the ~/tmp directory to your liking)

google-chrome --disable-site-isolation-trials --disable-web-security --user-data-dir="~/tmp"

Note : This solution will start chrome in an isolated sandbox and it will not affect the main chrome profile.

Henkel answered 31/3, 2019 at 14:53 Comment(17)
This is the only solution works for me. I have run this chrome.exe --disable-site-isolation-trials --disable-web-security --user-data-dir="D:\temp" on run window on windows 10. Thanks a lot.Clarettaclarette
HAIR PULLING ARGHGHGH - doesn't seem to work anymoreDesiccant
Adding --disable-site-isolation-trials really helped me in my case, Chrome v 75.0, Selenium Web Driver, Java. Thanks!Wheatear
If you just need to test a site with cors, use Safari, where you just need to turn on and off options, instead of launching another instance of the browser or killing instances: [https://mcmap.net/q/45698/-disabling-same-origin-policy-in-safari ]Tense
This is the only thing that worked in Chrome latest version as of July 2020.Filet
i use exactly this version 87.0.4280.66 and this solution not works in linux, even installing cors extentions not works at allMcdonnell
It works for me on Linux, but with a little modification google-chrome --disable-site-isolation-trials --disable-web-security --user-data-dir="/tmp"Irick
which version this will be changed?Subspecies
I have version 95, but adding --disable-site-isolation-trials does not work. Any workaround for this?Officiant
@Officiant , just tested it, it works on windowsHenkel
Doesn't work on chrome 96Francesco
@Aphax, nope , it works, just tested that on Version 96.0.4664.45 (Official Build) (64-bit).Henkel
As expected, it works with chromium also.Humble
This solution is the working one, on Chrome Version 97.0.4692.99. Thank you!Refinement
Seems --force-fieldtrials=SiteIsolationExtensions/Control may workSeparator
this worked on latest version for chromeGaleiform
I ran this command but now when I go to run my .NET Core rest API I get the following error: System.AggregateException: 'An error occurred while writing to logger(s). (A timeout occurred after 30000ms selecting a server using CompositeServerSelector{ Selectors = MongoDB.Driver.MongoClient+AreSessionsSupportedServerSelector, LatencyLimitingServerSelector{ AllowedLatencyRange = 00:00:00.0150000 }, OperationsCountServerSelector }. Client view of cluster state is { ClusterId : "1", Type : "Unknown", State : "Disconnected", Servers : [] }.)'Bullington
C
100

For windows users with **Chrome Versions 60.0.3112.78 (the day the solution was tested and worked) and at least until today 24.11.2022 (ver. 106.0.5249.119 (Official Build) (64-bit)). You do not need to close any chrome instance.

  1. Create a shortcut on your desktop
  2. Right-click on the shortcut and click Properties
  3. Edit the Target property
  4. Set it to "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --disable-web-security --user-data-dir="C:/ChromeDevSession"
  5. Start chrome and ignore the message that says --disable-web-security is not supported!

BEWARE NOT TO USE THIS PARTICULAR BROWSER INSTANCE FOR BROWSING BECAUSE YOU CAN BE HACKED WITH IT!

Calabria answered 1/8, 2017 at 9:27 Comment(9)
Worked like a charm. I can't believe Chrome doesn't allow developers to disable this without starting a new session. At least they have a way though.Kappenne
and can you still use chrome debugging on your source code?Concenter
just tested, you can still use dev tool under this mode.Foreside
This solution still works as of chrome version 71 Thanks so much!Unexpected
Works with 72.0.3626.109. Helped a lot!Savitt
"[...]YOU CAN BE HACKED WITH IT". How?Humble
@JannisIoannou please search the web for --disable-web-security flag. The explanation is too much for a comment.Calabria
This method still works: Version 106.0.5249.119 (Official Build) (64-bit)Enrico
Basically any site can make a request to another site as you if you disable web security Say you visit hack3rs-site.com which makes a post request to facebook.com to create a post, normally that request would be blocked by CORS, but by disabling this security the request will go through and if you were authenticated that request will use your existing cookiesHysteroid
C
78

EDIT 3: Seems that the extension no longer exists... Normally to get around CORS these days I set up another version of Chrome with a separate directory or I use Firefox with https://addons.mozilla.org/en-US/firefox/addon/cors-everywhere/ instead.

EDIT 2: I can no longer get this to work consistently.

EDIT: I tried using the just the other day for another project and it stopped working. Uninstalling and reinstalling the extension fixed it (to reset the defaults).

Original Answer:

I didn't want to restart Chrome and disable my web security (because I was browsing while developing) and stumbled onto this Chrome extension.

Chrome Web Store Allow-Control-Allow-Origin: *
(https://chrome.google.com/webstore/detail/allow-control-allow-origi/nlfbmbojpeacfghkpbjhddihlkkiljbi?hl=en)

Basically it's a little toggle switch to toggle on and off the Allow-Access-Origin-Control check. Works perfectly for me for what I'm doing.

Colorific answered 20/6, 2014 at 6:3 Comment(8)
how I achieve and integrate with my extension as my extension needs to access cross domain. I cannot force user to open the browser wth disable-web-securityPaschasia
It only allows AJAX requests not normal webpages and extensions to access webpages.Ventre
This extension won't work for local files, unfortunately. Stick to the --disable-web-security switch in that case.Jenjena
@Jenjena It's not really meant to. Consider though that you can use --allow-file-access-from-files instead of disabling all web security.Colorific
Extension is useful, works as expected. BUT If I toggle on this extension then I can't browse youtube, google docs etc.. I'm sure problem in extension.Ribald
Yup, you are right, I am getting this same problem. The specific error in the Javascript console is this one (no idea if there's a work around) #19743896Colorific
Warning! Some sites won't let you log in with this extension enabled! Firebase console, for example.Gothurd
“the extension no longer exists” can you delete your answer or at least put Edit 3 at the top in boldPreponderant
L
64

Try this command on Mac terminal-

open -n -a "Google Chrome" --args --user-data-dir=/tmp/temp_chrome_user_data_dir http://localhost:8100/ --disable-web-security 

It opens another instance of chrome with disabled security and there is no CORS issue anymore. Also, you don't need to close other chrome instances anymore. Change localhost URL to your's one.

Lawtun answered 26/12, 2017 at 9:4 Comment(2)
Most of the command-line answers above made no improvement for me on macOS. However this post alfilatov.com/posts/run-chrome-without-cors and the command line open worked for me. It is the same as the command above so voting up.Carious
This worked for me in 2023, on Chrome 119.0.6045.159 (Official Build) (64-bit), in Debian 12. Small difference: I have to drop open -n -a and change "Google Chrome" to google-chrome, like this: google-chrome --user-data-dir=/tmp/temp_chrome_user_data_dir http://localhost:8100/ --disable-web-security. I just added an ampersand and output redirection to /dev/null, but thanks for this.Gastropod
C
57

Seems none of above solutions are actually working. The --disable-web-security is no longer supported in recent chrome versions.

Allow-Control-Allow-Origin: * - chrome extension partially solved the problem. It works only if your request is using GET method and there's no custom HTTP Header. Otherwise, chrome will send OPTIONS HTTP request as a pre-flight request. If the server doesn't support CORS, it will respond with 404 HTTP status code. The plugin can't modify the response HTTP status code. So chrome will reject this request. There's no way for chrome plugin to modify the response HTTP status code based on current chrome extension API. And you can't do a redirect as well for XHR initiated request.

Not sure why Chrome makes developers life so difficult. It blocks all the possible ways to disable XSS security check even for development use which is totally unnecessary.

After days struggle and research, one solution works perfectly for me: to use corsproxy. You have two options here: 1. use [https://cors-anywhere.herokuapp.com/] 2. install corsproxy in the local box: npm install -g corsproxy

[Updated on Jun 23, 2018] Recent I'm developing an SPA app which need to use corsproxy again. But seem none of the corsproxy on the github can meet my requirement.

  • need it to run inside firewall for security reason. So I can't use https://cors-anywhere.herokuapp.com/.
  • It has to support https as chrome will block no-https ajax request in an https page.
  • I need to run on nodejs. I don't want to maintain another language stack.

So I decide to develop my own version of corsproxy with nodejs. It's actually very simple. I have published it as a gist on the github. Here is the source code gist: https://gist.github.com/jianwu/8e76eaec95d9b1300c59596fbfc21b10

  • It's in plain nodejs code without any additional dependencies
  • You can run in http and https mode (by passing the https port number in command line), to run https, you need to generate cert and key and put them in the webroot directory.
  • It also serves as static file server
  • It supports pre-flight OPTION request as well.

To start the CORSProxy server (http port 8080): node static_server.js 8080

to access the proxy: http://host:8080/http://www.somesite.com

Camail answered 12/1, 2015 at 7:51 Comment(10)
If you're going to go to that extent, you could always just host a web server locally or remotely that pulls the content from the webpage you desire and then set the proper CORS headers on that.Colorific
I have thought of this route before. But this need some coding, especially in my case, I need to call several services which are originated from different domains. So I have to map different URL pattern to different domains. This is exactly what corsproxy has done for us. And it works perfectly.Camail
Of course doesn't work with https which is something google and mozilla want to enforce now on every page.Ventre
Not true.. The way mentioned in accepted answer worked for me.. As it mentions, Chrome 49 onwards command 'chrome.exe --disable-web-security --user-data-dir' worked for me..Raama
--disable-web-security is "unsupported" but continue to work just fineTingley
Chromium 53, --disable-web-security --user-data-dir didn't work for meHachmin
In 53+ you need to actual provide a unique user data directory which is different from your normal directory. This creates a new profile for the insecure environment. --user-data-dir needs to be set equal to something, such as in Olas answer above. If you really want to, you CAN set it equal to your actual normal user profile folder, but this is highly discouraged as it leaves your normal profile open to accidental attacks if you start normal browsing while in that mode.Sudoriferous
Can you provide an example on how to use this? What URL should I use after running the Node.js server? Is it similar to CORS-ANYWHERE?As
@wwjdm, you are right, it's similar, you can specify the url in the following format host:8080/http://www.somesite.com, i have added it to the jsdoc in the gist.Camail
Unfortunately, corsproxy doesn't work anymore because of deprecated Node API. TypeError: Os.tmpDir is not a functionEncaustic
T
56

I find the best way to do this is duplicate a Chrome or Chrome Canary shortcut on your windows desktop. Rename this shortcut to "NO CORS" then edit the properties of that shortcut.

in the target add --disable-web-security --user-data-dir="D:/Chrome" to the end of the target path.

your target should look something like this:

Update: New Flags added.

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --disable-web-security --user-data-dir="D:/Chrome"

enter image description here

Tripartition answered 13/1, 2016 at 23:48 Comment(4)
This just gives me 404 now instead of pre-flight errorSmallscale
A 404 error would be a server related error and not a Google Chrome error.Tripartition
@Tripartition This answer is no longer valid in the latest version of chrome. You have to add --disable-web-security --user-data-dir="D:/Chrome"Deb
It works for me in Chrome latest (Version 119.0.6045.160 (Official Build) (64-bit))Precritical
A
53

For Windows... create a Chrome shortcut on your desktop.
Right-click > properties > Shortcut
Edit "target" path :

"C:\Program Files\Google\Chrome\Application\chrome.exe" --args --disable-web-security

(Change the 'C:....\chrome.exe' to where ever your chrome is located).

et voilà :)

Ardith answered 27/8, 2013 at 12:43 Comment(4)
As of today 08/27/20013 it's works for me, allowing me to do Ajax on my own localhost.Ardith
got "you are using an unsupported command line tag: --disable-web-security" with Canary version 53Riki
@Riki you can still use the switch. That warning is part of Google's war on insecurity (a good thing). Also, as of version 55+ you need to also use --user-data-dir=<some other directory here> so Google doesn't want you mixing insecure rules with your normal profiles.Sudoriferous
Thank you, I have forgotten about my Chrome is not in path, which mean I have to direct it to its folder.Entomology
S
29
  1. Create a shortcut:

Create new shortcut


  1. Paste the command:

cmd /c start chrome --disable-web-security --user-data-dir="c:\temp\chrome"


  1. Run as administrator
Sheelagh answered 11/4, 2020 at 20:42 Comment(1)
This one works for meNiven
S
26

For OSX, run the following command from the terminal:

open -na Google\ Chrome --args --disable-web-security --user-data-dir=$HOME/profile-folder-name

This will start a new instance of Google Chrome with a warning on top.

CAUTION: if you use --user-data-dir then chrome disconnect with you user-data folder (and logout you from all your sites) - even if you run it again without any params. To rollback this, you need to open in above way but without that prameter.

Seve answered 14/11, 2019 at 20:26 Comment(0)
I
20

For Selenium Webdriver, you can have selenium start Chrome with the appropriate arguments (or "switches") in this case.

 @driver = Selenium::WebDriver.for(:Chrome, { 
       :detach => false,
       :switches => ["--disable-web-security"]
    })
Interpretive answered 27/3, 2012 at 13:7 Comment(2)
that's two preceeding dashes for disable-web-security. it my browser it made them look like one looong dash.Interpretive
I've wrote a small post about chrome without corsCincture
C
19

You can use this chrome plugin called "Allow-Control-Allow-Origin: *" ... It make it a dead simple and work very well. check it here: *

Chrome extenstion

Crosscurrent answered 2/3, 2017 at 14:21 Comment(2)
It sets "evil.com" website as a origin, looks suspicious.Abubekr
No longer functional as per the date of this comment. Would recommend just using the flag route.Aspire
P
16

FOR MAC USER ONLY

open -n -a /Applications/Google\ Chrome.app --args --user-data-dir="/tmp/someFolderName" --disable-web-security
Pringle answered 16/5, 2017 at 9:0 Comment(2)
how to revert this change @saurabHyperbolize
@MohasinAli close all chrome windows and just run it like normally. It only affects the instance you ran with this argument. If you run it again without any arguments, this change is not applied.Cobb
R
15

You can simply use this chrome extension Allow-Control-Allow-Origin

just click the icon of the extensnion to turn enable cross-resource sharing ON or OFF as you want

Remote answered 29/1, 2015 at 14:49 Comment(5)
The link is dead.Discriminator
It is not. And yeah it's working. But we are here cause we now what a command means so use the above solutions before this!Ringmaster
@Jánosi-BorsosRóbert who are included in your "we", and how could your knowledge of the meaning of a command bring you here? FYI: Your command is imprecise, and I did not obey ;)Fridlund
True that @Superole. I meant that I think it's better to use a command than installing an extension.Ringmaster
It doesn't work for iframe. It disables only part of CORSUnlettered
J
14

If you are using Google Chrome on Linux, following command works.

google-chrome  --disable-web-security
Jacklight answered 15/6, 2012 at 9:46 Comment(0)
C
14

This Chrome plugin works for me: Allow-Control-Allow-Origin: * - Chrome Web Store

Conclusive answered 12/9, 2014 at 3:29 Comment(2)
This plugin broke in my browser and started breaking all the XHR things. Use with caution.Tripartition
This plugin is removed from chrome storeCarve
I
12

On Linux- Ubuntu, to run simultaneously a normal session and an unsafe session run the following command:

google-chrome  --user-data-dir=/tmp --disable-web-security
Incurvate answered 14/9, 2018 at 4:23 Comment(0)
T
8

Following on Ola Karlsson answer, indeed the best way would be to open the unsafe Chrome in a different session. This way you don't need to worry about closing all of the currently opened tabs, and also can continue to surf the web securely with the original Chrome session.

These batch files should just work for you on Windows.

Put it in a Chrome_CORS.bat file for easy use

start "" "c:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --user-data-dir="c:/_chrome_dev" --disable-web-security

This one is for Chrome Canary. Canary_CORS.bat

start "" "c:\Users\%USERNAME%\AppData\Local\Google\Chrome SxS\Application\chrome.exe" --user-data-dir="c:/_canary_dev" --disable-web-security
Tingley answered 14/1, 2016 at 20:31 Comment(3)
This is a pointless use of a batch file. A shortcut would be much better for this. Just put everything after the first pair of quotes into the shortcut target.Sudoriferous
It doesn't really matter. Yet in a batch you can do more things like deleting the user-data-dir after you close the browser, for example.Tingley
True, adding behavior outside of just launching would be useful, but for most people who need this at length, having a persistent user directory is helpful (for example with installed extensions)Sudoriferous
M
8
chromium-browser --disable-web-security --user-data-dir=~/ChromeUserData/
Mailbox answered 20/5, 2016 at 7:2 Comment(0)
H
8

for mac users:

open -a "Google Chrome" --args --disable-web-security --user-data-dir

and before Chrome 48, you could just use:

open -a "Google Chrome" --args --disable-web-security
Hyperthermia answered 31/8, 2016 at 19:41 Comment(1)
Thanks. This works on the latest Chrome 73 that included the new CORB security policy.Hemorrhoid
B
7

On Windows 10, the following will work.

<<path>>\chrome.exe --allow-file-access-from-files --allow-file-access --allow-cross-origin-auth-prompt
Bertle answered 29/12, 2015 at 17:16 Comment(2)
I am surprised that your answer was downvoted. It worked very well for me on local files with the latest Chrome version.Fain
@CHANist: That is perhaps why the OP said, "On Windows 10"...?Tellurium
W
7

this is an ever moving target.... today I needed to add another flag to get it to work: --disable-site-isolation-trials

OS X: open /Applications/Google\ Chrome.app --args --user-data-dir="/var/tmp/Chrome_dev_2" --disable-web-security --disable-site-isolation-trials

Whyalla answered 3/1, 2019 at 15:39 Comment(0)
W
6

Only for OSX Catalina the below command works for me.

open -n -a /Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome --args --user-data-dir="/tmp/chrome_dev_test" --disable-web-security

Wilburn answered 22/5, 2022 at 17:50 Comment(0)
A
5

There is a Chrome extension called CORS Toggle.

Click here to access it and add it to Chrome.

After adding it, toggle it to the on position to allow cross-domain requests.

Alcaraz answered 11/12, 2016 at 3:21 Comment(1)
The link is dead.Discriminator
S
5

Used below command in Ubuntu to start chrome (disable same origin policy and open chrome in detached mode):

nohup google-chrome --disable-web-security --user-data-dir='/tmp' &
Sigismundo answered 24/12, 2019 at 9:59 Comment(0)
O
3

For Windows:

(using windows 8.1, chrome 44.0)

First, close google chrome.

Then, open command prompt and go to the folder where 'chrome.exe' is.

( for me: 'chrome.exe' is here "C:\Program Files (x86)\Google\Chrome\Application".

So I type: cd C:\Program Files (x86)\Google\Chrome\Application )

now type: chrome.exe --disable-web-security

a new window of chrome will open.

Ornithischian answered 2/8, 2015 at 6:39 Comment(0)
I
1

Remove Cors origin issue from the chrome browser in windows.

click window and search run once the run app is open paste the below command on the open and click ok.

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --disable-web-security --disable-gpu --user-data-dir=~/chromeTemp

Before running this command please make sure all you chrome browsers are closed.

Interradial answered 8/8, 2023 at 8:47 Comment(0)
P
1

This is the that works for me on Macos:

open -n -a /Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome --args --user-data-dir="/tmp/chrome_dev_test" --disable-web-security
Pettus answered 6/3 at 6:36 Comment(0)
A
0

On a Windows PC, use an older version of Chrome and the command will work for all you guys. I downgraded my Chrome to 26 version and it worked.

Athalla answered 18/2, 2014 at 15:42 Comment(1)
U dont need a older version of chrome use this full command --disable-web-security --user-data-dir="D:/Chrome"Deb
D
0

I use this sometimes, for posting a localhost front-end site to a localhost back-end API (e.g. React to an old .NET API). I created a separate shortcut on my Windows 10 desktop, so that it never is used for normal browsing, only for debugging locally. I did the following:-

  1. Right click on desktop, add new shortcut
  2. Add the target as "[PATH_TO_CHROME]\chrome.exe" --disable-web-security
  3. Click OK.

You will get a warning on load of this browser, that it is not secure, just take care with what you browser on it. I tend to rename this new shortcut on the desktop, something in capital, and move it away from my other icons, so it can't be confused for normal Chrome.

Hope this helps!

Disdainful answered 28/12, 2017 at 15:5 Comment(0)
P
0

Try going to this page and disabling the domain security policy for your website domain.

chrome://net-internals/#hsts
Pathway answered 15/4, 2019 at 13:15 Comment(1)
Please, explain. At this page at the bottom I see Input a domain name to delete its dynamic domain security policies (HSTS and Expect-CT). (You cannot delete preloaded entries.):.Discriminator
S
0

We can Override network response header which is a new feature in Chrome113 Dev Tools

Open the Network tab then click on the failed request. And at the Response Headers section search for the header request Access-Control-Allow-Origin and set it to allow all origins (*).

enter image description here

Refresh the page and the error of CORS will disappear and data would be fetched!

We can also override multiple requests at once by just clicking on Header overrrides at the Response Headers section. And sets Apply to property to *.json and reloads the page again.

Suazo answered 22/7, 2023 at 13:4 Comment(0)
K
-1

Disable this flag is chrome - chrome://flags/#reduced-referrer-granularity it should work

Kovno answered 21/3, 2021 at 7:51 Comment(1)
Not seeing that on 89.0.4389.90Papillary
T
-1

In Windows:

create a shortcut and set target:

"C:\Program Files\Google\Chrome\Application\chrome.exe" --disable-site-isolation-trials --disable-web-security --user-data-dir="C:/ChromeDevSession"

Torpedoman answered 11/12, 2022 at 18:12 Comment(0)
D
-1

Nothing worked - but adding this app.use(cors()); has worked for me.

Simply, use this once you initialize.

const app = express();
app.use(cors());
Diao answered 8/8, 2023 at 8:13 Comment(0)
G
-3

The Allow-Control-Allow-Origin plugin for Chrome does not work. This is for MacOS

I added alias chrome='open -n -a /Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome --args --user-data-dir --disable-web-security' to my .profile as an alias.

The other commands will disable my other extensions and this will boot your normal chrome with cors disabled

Godman answered 9/8, 2019 at 22:9 Comment(2)
If you just need to test a site with cors, use Safari, where you just need to turn on and off options, instead of launching another instance of the browser: [https://mcmap.net/q/45698/-disabling-same-origin-policy-in-safari]Tense
Do not disable CORS for normal browser, it is unsafe. Do it only for testing/developing your own sitesPreponderant

© 2022 - 2024 — McMap. All rights reserved.