# Serverless tutorial bug with CORS config

**URL:** <https://discourse.sst.dev/t/serverless-tutorial-bug-with-cors-config/2111>\
**Category:** Chapter Comments\
**Created:** [October 12, 2020, 6:12am UTC](https://discourse.sst.dev/t/serverless-tutorial-bug-with-cors-config/2111 "2020-10-12T06:12:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![fishtaco](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/fishtaco/32/994_2.png) [@fishtaco](https://discourse.sst.dev/u/fishtaco)\
**Post date:** [October 12, 2020, 6:12am UTC](https://discourse.sst.dev/t/serverless-tutorial-bug-with-cors-config/2111/1 "2020-10-12T06:12:37Z")

</div>

This is a question about the Serverless Stack tutorial at [https://serverless-stack.com/](https://serverless-stack.com/).

During the segment “Create an S3 Bucket for File Uploads”, I am configuring CORS by typing in the recommended block of XML into the editor. This XML is rejected with API response “Expected params.CORSConfiguration.CORSRules to be an Array”.

The XML is well-formed and valid, and seems to conform to the rules of CORS configuration shown in the AWS documentation link below. Is there a fix?

> **[Cross-origin resource sharing (CORS) - Amazon Simple Storage Service](https://docs.aws.amazon.com/AmazonS3/latest/dev/cors.html)**

Thanks

---

<div class="post-metadata">

**Author:** ![fishtaco](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/fishtaco/32/994_2.png) [@fishtaco](https://discourse.sst.dev/u/fishtaco)\
**Post date:** [October 12, 2020, 10:39pm UTC](https://discourse.sst.dev/t/serverless-tutorial-bug-with-cors-config/2111/2 "2020-10-12T22:39:31Z")

</div>

Ok, I can narrow the problem down. It is happening for me only in the “new” version of the S3 Bucket UI. If I switch to the old version, I can enter the CORS configuration with no difficulty.

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [October 15, 2020, 7:01pm UTC](https://discourse.sst.dev/t/serverless-tutorial-bug-with-cors-config/2111/3 "2020-10-15T19:01:10Z")

</div>

Oh that’s super weird. Glad you figured out the issue.

---

<div class="post-metadata">

**Author:** ![jeffcordova](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jeffcordova/32/1232_2.png) [@jeffcordova](https://discourse.sst.dev/u/jeffcordova)\
**Post date:** [October 29, 2020, 10:42am UTC](https://discourse.sst.dev/t/serverless-tutorial-bug-with-cors-config/2111/4 "2020-10-29T10:42:41Z")

</div>

I encountered the same error. Turns out, S3 now expects the rules to be an array JSON format. For those who encounters this same error, please see new format below. 🙂

```json
[
    {
        "AllowedHeaders": [
            "*"
        ],
        "AllowedMethods": [
            "GET",
            "PUT",
            "POST",
            "HEAD",
            "DELETE"
        ],
        "AllowedOrigins": [
            "*"
        ],
        "ExposeHeaders": [],
        "MaxAgeSeconds": 3000
    }
]

```

---

<div class="post-metadata">

**Author:** ![daryl.codes](https://avatars.discourse-cdn.com/v4/letter/d/3bc359/32.png) [@daryl.codes](https://discourse.sst.dev/u/daryl.codes)\
**Post date:** [October 31, 2020, 1:30am UTC](https://discourse.sst.dev/t/serverless-tutorial-bug-with-cors-config/2111/5 "2020-10-31T01:30:22Z")

</div>

i am also having trouble with this.

I copied and pasted  
[  
{  
“AllowedHeaders”: [  
“ _"  
],  
“AllowedMethods”: [  
“GET”,  
“PUT”,  
“POST”,  
“HEAD”,  
“DELETE”  
],  
“AllowedOrigins”: [  
"_ ”  
],  
“ExposeHeaders”: [],  
“MaxAgeSeconds”: 3000  
}  
]

and gave me the same error.

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [November 13, 2020, 3:20am UTC](https://discourse.sst.dev/t/serverless-tutorial-bug-with-cors-config/2111/6 "2020-11-13T03:20:55Z")

</div>

Hmm the one you posted seems different from the one above?

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [November 13, 2020, 3:58am UTC](https://discourse.sst.dev/t/serverless-tutorial-bug-with-cors-config/2111/7 "2020-11-13T03:58:11Z")

</div>

Thanks all. Updating the new chapter with this:

> **[Handle CORS in S3 for File Uploads](https://serverless-stack.com/chapters/handle-cors-in-s3-for-file-uploads.html)**
>
> In this chapter we’ll be configuring CORS (or cross-origin resource sharing) for our AWS S3 bucket. This will allow the users of our React web app to upload files directly to our S3 bucket. Even though they’ll be hosted on two different domains.
