# CORS Plugin issue with v1.0.3

**URL:** <https://discuss.konghq.com/t/cors-plugin-issue-with-v1-0-3/2838>\
**Category:** Questions\
**Created:** [February 17, 2019, 7:02pm UTC](https://discuss.konghq.com/t/cors-plugin-issue-with-v1-0-3/2838 "2019-02-17T19:02:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rossee](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/rossee/32/764_2.png) [@rossee](https://discuss.konghq.com/u/rossee)\
**Post date:** [February 17, 2019, 7:02pm UTC](https://discuss.konghq.com/t/cors-plugin-issue-with-v1-0-3/2838/1 "2019-02-17T19:02:59Z")

</div>

I’m trying to install the CORS plugin globally and keep hitting the following error:  
`{"message":"schema violation (config.methods: expected one of: HEAD, GET, POST, PUT, PATCH, DELETE)","name":"schema violation","fields":{"config":{"methods":"expected one of: HEAD, GET, POST, PUT, PATCH, DELETE"}},"code":2}`  
The methods are defined in the plugin syntax by this:  
`--data "config.methods=HEAD, GET, POST, PUT ,PATCH, DELETE"`

The plugin works fine with a single method, but will not allow more than that. Under v.14, the plugin allowed multiple methods to be defined.

---

<div class="post-metadata">

**Author:** ![thibaultcha](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/thibaultcha/32/340_2.png) [@thibaultcha](https://discuss.konghq.com/u/thibaultcha)\
**Post date:** [February 19, 2019, 6:19pm UTC](https://discuss.konghq.com/t/cors-plugin-issue-with-v1-0-3/2838/2 "2019-02-19T18:19:29Z")

</div>

@rossee Hi,

Are you using the proper syntax for arguments introduced in 0.13 for new endpoints (`/routes`, `/services`), and used in 1.0 for the `/plugins` endpoint? I have no problem specifying multiple `methods` in 1.0.3 with both `application/x-www-form-urlencoded`:

```auto
http -v :8001/services/323b5367-4a33-4872-83b3-1b803f9604b2/plugins 'name=cors' 'config.methods[]=GET' 'config.methods[]=HEAD' -f
POST /services/323b5367-4a33-4872-83b3-1b803f9604b2/plugins HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
Connection: keep-alive
Content-Length: 60
Content-Type: application/x-www-form-urlencoded; charset=utf-8
Host: localhost:8001
User-Agent: HTTPie/0.9.4

name=cors&config.methods%5B%5D=GET&config.methods%5B%5D=HEAD

HTTP/1.1 201 Created
Access-Control-Allow-Origin: *
Connection: keep-alive
Content-Length: 351
Content-Type: application/json; charset=utf-8
Date: Tue, 19 Feb 2019 18:14:55 GMT
Server: kong/1.0.3

{
    "config": {
        ...
        "methods": [
            "GET",
            "HEAD"
        ],
    },
    ...
    "service": {
        "id": "323b5367-4a33-4872-83b3-1b803f9604b2"
    }
}

```

And `application/json`:

```auto
 http -v :8001/services/323b5367-4a33-4872-83b3-1b803f9604b2/plugins name=cors config:='{"methods":["GET", "HEAD"]}'       
POST /services/323b5367-4a33-4872-83b3-1b803f9604b2/plugins HTTP/1.1
Accept: application/json
Accept-Encoding: gzip, deflate
Connection: keep-alive
Content-Length: 56
Content-Type: application/json
Host: localhost:8001
User-Agent: HTTPie/0.9.4

{
    "config": {
        "methods": [
            "GET",
            "HEAD"
        ]
    },
    "name": "cors"
}

HTTP/1.1 201 Created
Access-Control-Allow-Origin: *
Connection: keep-alive
Content-Length: 351
Content-Type: application/json; charset=utf-8
Date: Tue, 19 Feb 2019 18:18:40 GMT
Server: kong/1.0.3

{
    "config": {
        ...
        "methods": [
            "GET",
            "HEAD"
        ],
    },
    ...
    "service": {
        "id": "323b5367-4a33-4872-83b3-1b803f9604b2"
    }
}

```

---

<div class="post-metadata">

**Author:** ![AlexanderGerasymenko](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@AlexanderGerasymenko](https://discuss.konghq.com/u/AlexanderGerasymenko)\
**Post date:** [March 21, 2019, 12:12pm UTC](https://discuss.konghq.com/t/cors-plugin-issue-with-v1-0-3/2838/3 "2019-03-21T12:12:45Z")

</div>

Hi,

same issue here

curl -X POST [http://local:8001/services/stage-service/plugins](http://local:8001/services/stage-service/plugins) --data “name=cors” --data “config.origins=https://stage.local” --data “config.methods=POST, GET” --data “config.headers=Accept, Accept-Version, Content-Length, Content-MD5, Content-Type, Date, X-Auth-Token” --data “config.exposed\_headers=X-Auth-Token” --data “config.credentials=true” --data “config.max\_age=3600”

returns

{“message”:“schema violation (config.methods: expected one of: HEAD, GET, POST, PUT, PATCH, DELETE)”,“name”:“schema violation”,“fields”:{“config”:{“methods”:“expected one of: HEAD, GET, POST, PUT, PATCH, DELETE”}},“code”:2}

---

<div class="post-metadata">

**Author:** ![thibaultcha](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/thibaultcha/32/340_2.png) [@thibaultcha](https://discuss.konghq.com/u/thibaultcha)\
**Post date:** [March 21, 2019, 4:40pm UTC](https://discuss.konghq.com/t/cors-plugin-issue-with-v1-0-3/2838/4 "2019-03-21T16:40:37Z")

</div>

@AlexanderGerasymenko Hi, and welcome!

Same issue: you are using the old array notation (comma-separated) which isn’t accepted anymore as of Kong 1.0. Please read my above reply which explains how to send arrays with both of Kong’s Admin  
s accepted Content-Type.

---

<div class="post-metadata">

**Author:** ![AlexanderGerasymenko](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@AlexanderGerasymenko](https://discuss.konghq.com/u/AlexanderGerasymenko)\
**Post date:** [March 21, 2019, 7:25pm UTC](https://discuss.konghq.com/t/cors-plugin-issue-with-v1-0-3/2838/5 "2019-03-21T19:25:53Z")

</div>

Hey @thibaultcha,

I followed this instruction [https://docs.konghq.com/hub/kong-inc/cors/](https://docs.konghq.com/hub/kong-inc/cors/) for kong v. 1.0.x. Am I referring to a wrong documentation? Just so for me to know if I can proceed learning kong by it.

---

<div class="post-metadata">

**Author:** ![rossee](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/rossee/32/764_2.png) [@rossee](https://discuss.konghq.com/u/rossee)\
**Post date:** [March 21, 2019, 10:52pm UTC](https://discuss.konghq.com/t/cors-plugin-issue-with-v1-0-3/2838/6 "2019-03-21T22:52:09Z")

</div>

I can confirm that this works via application/json. I think the issue is that the documentation has not been updated to deprecate the old array notation (comma-separated). Kong 1.0.x still shows this as a valid config. This tripped us up as well. Thanks!
