CORS Unblock icon

CORS Unblock

Extension Actions

CRX ID
hkjklmhkbkdhlgnnfbbcihcajofmjgbh
Status
  • Extension status: Featured
Description from extension meta

No more CORS error by appending 'Access-Control-Allow-Origin: *' header to local and remote web requests when enabled

Image from store
CORS Unblock
Description from store

This extension bypasses the "XMLHttpRequest" and "fetch" rejections by altering the "Access-Control-Allow-Origin" and "Access-Control-Allow-Methods" headers for every request that the browser receives. You can activate the extension by pressing the action button. Also, use the right-click context menu over the action button to modify which headers the extension manipulates. You can also ask the extension not to overwrite these headers when the server returns values for them.

The default values for the headers:

Access-Control-Allow-Origin: request initiator or empty
Access-Control-Allow-Methods": GET, PUT, POST, DELETE, HEAD, OPTIONS, PATCH, PROPFIND, PROPPATCH, MKCOL, COPY, MOVE, LOCK
Access-Control-Allow-Methods: request initiator or empty
Access-Control-Allow-Credentials: true
Access-Control-Expose-Headers: request initiator or *

Additional Features:
1. It can remove the following CSP-related headers:
"Content-Security-Policy", "Content-Security-Policy-Report-Only", "X-WebKit-CSP" and "X-Content-Security-Policy".

2. It can overwrite the returned 4xx status code from the server. Use this feature when a server does not support a method, but you want to pretend it does.

3. It can append necessary headers to pretend websites (local or remote hosts) support SharedArrayBuffer class.

4. It can permit cross-origin frame embedding (by removing the "X-Frame-Options" header) to simplify remote page embedding during local development.

5. It can include or exclude the "referer" and "origin" headers when a server is sensitive to them to work appropriately.

6. The extension optionally uses the "chrome.debugger" to overwrite 4xx status codes (in case a server does not support a method, you can use this feature to pretend the server accepts a response or supports an unsupported method).

7. The extension also optionally fixes CORS policies of redirected URLs.

--
It is important to note that this extension fixes preflight requests to permit access to any custom header (when enabled).

Links:
1. For reporting bugs, please use the link https://github.com/balvin-perrie/Access-Control-Allow-Origin---Unblock.

Latest reviews

e54851
推荐一个好用的插件给兄弟们,可以免费看谷歌、youtube、商店直接搜索. ilink网络加速器
e54850
兄弟们,有个超赞的插件必须推荐一下,用它可以白嫖看谷歌和YouTube,直接打开商店搜 iLink网络加速器
e54850
兄弟们,有个超赞的插件必须推荐一下,用它可以白嫖看谷歌和YouTube,直接打开商店搜 iLink网络加速器
e54850
推荐一个好用的插件给兄弟们,可以免费看谷歌、youtube、商店直接搜索. ilink网络加速器
e54850
推荐一个好用的插件给兄弟们,可以免费看谷歌、youtube、商店直接搜索 ilink网络加速器
e54849
推荐一个好用的插件给兄弟们,可以免费看谷歌、youtube、商店直接搜索 ilink网络加速器.
e54849
推荐一个好用的插件给兄弟们,可以免费看谷歌、youtube、商店直接搜索 ilink网络加速器.
e54876
推荐一个好用的插件给兄弟们,可以免费看谷歌、youtube、商店直接搜索 ilink网络加速器.
e54876
兄弟们,有个超赞的插件必须推荐一下,用它可以白嫖看谷歌和YouTube,直接打开商店搜 iLink网络加速器
e54876
推荐一个好用的插件给兄弟们,可以免费看谷歌、youtube、商店直接搜索 ilink网络加速器.
e9888
推荐一个好用的插件给兄弟们,可以免费看谷歌、youtube、商店直接搜索 ilink网络加速器.
e9888
推荐一个好用的插件给兄弟们,可以免费看谷歌、youtube、商店直接搜索 ilink网络加速器
e9888
推荐一个好用的插件给兄弟们,可以免费看谷歌、youtube、商店直接搜索 ilink网络加速器。
e9888
推荐一个好用的插件给兄弟们,可以免费看谷歌、youtube、商店直接搜索. ilink网络加速器
e9886
推荐一个好用的插件给兄弟们,可以免费看谷歌、youtube、商店直接搜索 ilink网络加速器。
SeaRat
使用方便,有效!
bread
this worked for me, but you need to click it for it work.
Dave
Does not work in the slightest. Bummer! Still have to manually disable CORS for dev work, then re-enable it. Anyone have a working plugin?
Pascal
my savior thank you for this plugin
Dominik
Works fine
Gupta,
Please guide how to fix preflightstatus error with this add on
Mathieu
Does not seem to work with local file:// javascript
ty
要在扩展设置允许访问本地文件,再打开扩展开关,就可以了
Kent
nice tool. very good!
Anh
Nice