Sitelet https://github.com/googleapis/google-cloud-java/issues/1336
Skip to content

Can't set CORS to <Origin>*</Origin> when initiating resumable uploads? #1336

Description

@omerzach

https://cloud.google.com/storage/docs/cross-origin#How_CORS_Works:

When using the resumable upload protocol, the Origin from the first (start upload) request is always used to decide the Access-Control-Allow-Origin header in the response, even if you use a different Origin for subsequent requests. Therefore, you should either use the same Origin for the first and subsequent requests, or if the first request has a different Origin than subsequent requests, use the XML API with the CORS configuration set to *.

I'm initiating resumable uploads from my server, sending the generated upload URL to my clients (web/mobile apps), and then having them actually POST files to Google Cloud Storage. It seems I need CORS configured to <Origin>*</Origin> to support this, but I don't see a way to do so in the SDK. Is there a solution I'm missing?

Activity

  1. lesv commented on Oct 25, 2016

    @lesv
    Contributor

    Take a look at the Cors, Cors.Builder, and Cors.Origin classes in the javadocs

    I couldn't find an example, but the tests show creating and setting them.

  2. added
    type: feature request‘Nice-to-have’ improvement, new feature or different behavior or design.
    api: storageIssues related to the Cloud Storage API.
    on Oct 25, 2016
  3. omerzach commented on Oct 25, 2016

    @omerzach
    Author

    Yep I see how to create the Cors policy I need, but not how to associate it with the API request the SDK is making for me?

  4. omerzach commented on Oct 25, 2016

    @omerzach
    Author

    Looks like I have the exact same issue as this: danialfarid/ng-file-upload#1192

    In their PHP solution they add "Origin" => env('APP_ADDRESS') to their initial call that starts the resumable upload. I'd like to similarly add either * or my specific client address but don't see a way to do this with the SDK.

  5. lesv commented on Oct 25, 2016

    @lesv
    Contributor

    So, CORS is typically something you set once. (At least as I understand it)

    You set CORS on a bucket, and not AFAIK on an object. (Are you thinking something else)?

    Bucket.Builder has a cors(Iterable<Cors> cors) method
    BucketInfo.Builder also has a cors method.

    So, in looking, it appears that you can update a Bucket using a BucketInfo

         Cors cors = Cors.newBuilder()
            .setMaxAgeSeconds(100)
            .setOrigins(origins)
            .setResponseHeaders(headers)
            .setMethods(methods)
            .build();
    
        String bucketName = "my_unique_bucket";
        BucketInfo bucketInfo = BucketInfo.builder(bucketName).cors(cors).build();
        Bucket bucket = storage.update(bucketInfo);

    Note - the cors() method will become setCors() in the next release.

  6. mziccard commented on Oct 26, 2016

    @mziccard
    Contributor

    Hi @omerzach! Are you using google-cloud-java to create the resumable upload URL? If yes, can you share with us the code you are using?

    google-cloud-storage uses the JSON api under the hood. AFAIK when you create a resumable upload URL using the JSON api you need to preserve the same Origin that you used for the opening request in all subsequent upload requests.

    A possible workaround could be to override the Origin header in the request that opens the resumable URL, as it's done in danialfarid/ng-file-upload#1192. Unfortunately, at the moment google-cloud-storage does not expose such a option. In fact, we do not even expose a method to create a resumable URL in our Storage interface.

  7. omerzach commented on Oct 26, 2016

    @omerzach
    Author

    Yeah, looks like that's exactly the issue.

    So I guess the only solution is to directly call the endpoint to start the resumable upload with a custom origin instead of using the SDK?

    For what it's worth, I'm calling from Scala, not Java, but:

      val options: StorageOptions = StorageOptions.defaultInstance
      val storageRpc = new DefaultStorageRpc(options)
    
      val storageObject = {
        (new StorageObject)
          .setBucket(bucket)
          .setName(key)
          .setContentType(contentType)
          .setSize(BigInt(contentLength).bigInteger)
      }
    
      storageRpc.open(storageObject, Map.empty.asJava)
    
  8. mziccard commented on Oct 27, 2016

    @mziccard
    Contributor

    So I guess the only solution is to directly call the endpoint to start the resumable upload with a custom origin instead of using the SDK?

    Yeah that would be your best option for now. Provided the http client lets you override origin (wouldn't give that for granted). Have a look at the code in DefaultStorageRpc.open for an idea of how to open the resumable upload URL.

  9. added a commit that references this issue on Mar 30, 2026
  10. added a commit that references this issue on Apr 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

api: storageIssues related to the Cloud Storage API.type: feature request‘Nice-to-have’ improvement, new feature or different behavior or design.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions