Repository navigation
Can't set CORS to <Origin>*</Origin> when initiating resumable uploads? #1336
Description
Activity
- addedtype: feature request‘Nice-to-have’ improvement, new feature or different behavior or design.‘Nice-to-have’ improvement, new feature or different behavior or design.api: storageIssues related to the Cloud Storage API.Issues related to the Cloud Storage API.
on Oct 25, 2016 Yep I see how to create the Cors policy I need, but not how to associate it with the API request the SDK is making for me?
Looks like I have the exact same issue as this: danialfarid/ng-file-upload#1192
In their PHP solution they add
"Origin" => env('APP_ADDRESS')to their initial call that starts the resumable upload. I'd like to similarly add either*or my specific client address but don't see a way to do this with the SDK.So, CORS is typically something you set once. (At least as I understand it)
You set CORS on a bucket, and not AFAIK on an object. (Are you thinking something else)?
Bucket.Builderhas acors(Iterable<Cors> cors)method
BucketInfo.Builderalso has acorsmethod.So, in looking, it appears that you can update a Bucket using a
BucketInfoCors cors = Cors.newBuilder() .setMaxAgeSeconds(100) .setOrigins(origins) .setResponseHeaders(headers) .setMethods(methods) .build(); String bucketName = "my_unique_bucket"; BucketInfo bucketInfo = BucketInfo.builder(bucketName).cors(cors).build(); Bucket bucket = storage.update(bucketInfo);
Note - the
cors()method will becomesetCors()in the next release.Hi @omerzach! Are you using google-cloud-java to create the resumable upload URL? If yes, can you share with us the code you are using?
google-cloud-storageuses the JSON api under the hood. AFAIK when you create a resumable upload URL using the JSON api you need to preserve the same Origin that you used for the opening request in all subsequent upload requests.A possible workaround could be to override the
Originheader in the request that opens the resumable URL, as it's done in danialfarid/ng-file-upload#1192. Unfortunately, at the momentgoogle-cloud-storagedoes not expose such a option. In fact, we do not even expose a method to create a resumable URL in ourStorageinterface.Yeah, looks like that's exactly the issue.
So I guess the only solution is to directly call the endpoint to start the resumable upload with a custom origin instead of using the SDK?
For what it's worth, I'm calling from Scala, not Java, but:
val options: StorageOptions = StorageOptions.defaultInstance val storageRpc = new DefaultStorageRpc(options) val storageObject = { (new StorageObject) .setBucket(bucket) .setName(key) .setContentType(contentType) .setSize(BigInt(contentLength).bigInteger) } storageRpc.open(storageObject, Map.empty.asJava)So I guess the only solution is to directly call the endpoint to start the resumable upload with a custom origin instead of using the SDK?
Yeah that would be your best option for now. Provided the http client lets you override origin (wouldn't give that for granted). Have a look at the code in
DefaultStorageRpc.openfor an idea of how to open the resumable upload URL.- added a commit that references this issue
on Dec 22, 2025 - added a commit that references this issue
on Jan 6, 2026 - added a commit that references this issue
on Jan 22, 2026 - added a commit that references this issue
on Feb 24, 2026 - added a commit that references this issue
on Mar 11, 2026 - added a commit that references this issue
on Mar 12, 2026 - added a commit that references this issue
on Mar 23, 2026 - added a commit that references this issue
on Mar 30, 2026 - added a commit that references this issue
on Apr 1, 2026
https://cloud.google.com/storage/docs/cross-origin#How_CORS_Works:
I'm initiating resumable uploads from my server, sending the generated upload URL to my clients (web/mobile apps), and then having them actually POST files to Google Cloud Storage. It seems I need CORS configured to
<Origin>*</Origin>to support this, but I don't see a way to do so in the SDK. Is there a solution I'm missing?