# Dev, localhost and CORS

**URL:** <https://discourse.gohugo.io/t/dev-localhost-and-cors/4499>\
**Category:** support\
**Created:** [November 7, 2016, 9:12am UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499 "2016-11-07T09:12:43Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![gonzaloserrano](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/gonzaloserrano/32/2215_2.png) [@gonzaloserrano](https://discourse.gohugo.io/u/gonzaloserrano)\
**Post date:** [November 7, 2016, 9:12am UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499/1 "2016-11-07T09:12:43Z")

</div>

Hi there,

I’ve just started with Hugo. I chose the cactus theme ([http://themes.gohugo.io/theme/cactus/](http://themes.gohugo.io/theme/cactus/)) and launched the server with hugo server --config config.toml.

When i open the URL in the browser i get a Access to Font at  
’[http://localhost:1313/fonts/MonoSocialIconsFont-1.10.ttf](http://localhost:1313/fonts/MonoSocialIconsFont-1.10.ttf)’ from origin  
’[http://localhost:1313](http://localhost:1313)’ has been blocked by CORS policy: No  
’Access-Control-Allow-Origin’ header is present on the requested  
resource. Origin ‘[http://127.0.0.1:1313](http://127.0.0.1:1313)’ is therefore not allowed  
access…

Any hits? Should hugo set those headers for me somehow or it’s a theme thing?

Thanks.

---

<div class="post-metadata">

**Author:** ![bep](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/bep/32/3332_2.png) [@bep](https://discourse.gohugo.io/u/bep)\
**Post date:** [November 7, 2016, 10:05am UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499/2 "2016-11-07T10:05:32Z")

</div>

@digitalcraftsman may know more, but I see no such errors with that theme on localhost.

---

<div class="post-metadata">

**Author:** ![sairam](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/sairam/32/2198_2.png) [@sairam](https://discourse.gohugo.io/u/sairam)\
**Post date:** [November 7, 2016, 10:09am UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499/3 "2016-11-07T10:09:30Z")

</div>

Try to use either `localhost` or `127.0.0.1` in the configuration or try to use relative urls.

---

<div class="post-metadata">

**Author:** ![gonzaloserrano](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/gonzaloserrano/32/2215_2.png) [@gonzaloserrano](https://discourse.gohugo.io/u/gonzaloserrano)\
**Post date:** [November 7, 2016, 10:22am UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499/4 "2016-11-07T10:22:45Z")

</div>

Both domains have the same issue.

---

<div class="post-metadata">

**Author:** ![sairam](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/sairam/32/2198_2.png) [@sairam](https://discourse.gohugo.io/u/sairam)\
**Post date:** [November 7, 2016, 10:52am UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499/5 "2016-11-07T10:52:25Z")

</div>

Can you open localhost:1313 instead of 127.0.0.1:1313 ?

---

<div class="post-metadata">

**Author:** ![debrucer](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/debrucer/32/2228_2.png) [@debrucer](https://discourse.gohugo.io/u/debrucer)\
**Post date:** [November 8, 2016, 5:24am UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499/6 "2016-11-08T05:24:54Z")

</div>

Why isn’t it as simple as satisfying the “CORS policy” it says is doing the blocking?

---

<div class="post-metadata">

**Author:** ![digitalcraftsman](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/digitalcraftsman/32/4142_2.png) [@digitalcraftsman](https://discourse.gohugo.io/u/digitalcraftsman)\
**Post date:** [November 8, 2016, 9:25pm UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499/7 "2016-11-08T21:25:01Z")

</div>

> [@bep](#):
>
> @digitalcraftsman may know more, but I see no such errors with that theme on localhost.

I tested it locally as well but didn’t encountered the warnings you describe.

@sairam can you confirm this too?

---

<div class="post-metadata">

**Author:** ![sairam](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/sairam/32/2198_2.png) [@sairam](https://discourse.gohugo.io/u/sairam)\
**Post date:** [November 9, 2016, 4:53am UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499/8 "2016-11-09T04:53:03Z")

</div>

@gonzaloserrano has the problem. He could confirm.

I was just trying to help

---

<div class="post-metadata">

**Author:** ![digitalcraftsman](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/digitalcraftsman/32/4142_2.png) [@digitalcraftsman](https://discourse.gohugo.io/u/digitalcraftsman)\
**Post date:** [November 9, 2016, 6:35pm UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499/9 "2016-11-09T18:35:47Z")

</div>

> [@sairam](#):
>
> @gonzaloserrano has the problem. He could confirm.
> 
> I was just trying to help

I don’t want to deny that @gonzaloserrano has this problems. I just wanted to have a third party that could confirm it and maybe point us to the right direction. The problem is that @bep and I were not able to reproduce the error. This makes it harder to trace the source of the problem.

---

<div class="post-metadata">

**Author:** ![sairam](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/sairam/32/2198_2.png) [@sairam](https://discourse.gohugo.io/u/sairam)\
**Post date:** [November 9, 2016, 8:24pm UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499/10 "2016-11-09T20:24:33Z")

</div>

@digitalcraftsman The theme works fine and as expected when opened as `localhost:1313`, but not when opened as `127.0.0.1:1313`.

I see the font does not load on the latest version of Chrome on Mac OS Sierra which is expected (when opened through `127.0.0.1:1313`)

`{{ .Site.BaseURL }}` is being considered as `localhost` instead of `127.0.0.1` .

@gonzaloserrano could you provide the browser/OS information?

---

<div class="post-metadata">

**Author:** ![digitalcraftsman](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/digitalcraftsman/32/4142_2.png) [@digitalcraftsman](https://discourse.gohugo.io/u/digitalcraftsman)\
**Post date:** [November 9, 2016, 8:31pm UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499/11 "2016-11-09T20:31:32Z")

</div>

> [@sairam](#):
>
> I see the font does not load on the latest version of Chrome on Mac OS Sierra which is expected (when opened through 127.0.0.1:1313)

Ok, this was misunderstanding. Now I face the same message on the console. I tested it with Chrome and Firefox on Linux.

---

<div class="post-metadata">

**Author:** ![jehrhart](https://avatars.discourse-cdn.com/v4/letter/j/e95f7d/32.png) [@jehrhart](https://discourse.gohugo.io/u/jehrhart)\
**Post date:** [November 28, 2016, 7:26am UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499/12 "2016-11-28T07:26:15Z")

</div>

Has anyone figured this out? I cannot get fontawesome icons to load. It is specific to chrome and firefox, however safari does not have this issue. In searching the only work around I’ve found is in creating a .htaccess file but that doesn’t apply to HUGO, or does it? Can’t sort this out.

---

<div class="post-metadata">

**Author:** ![ddavo](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/ddavo/32/21302_2.png) [@ddavo](https://discourse.gohugo.io/u/ddavo)\
**Post date:** [July 29, 2024, 9:09pm UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499/13 "2024-07-29T21:09:53Z")

</div>

Same problem here, Im trying to make some dataviz with an API, and the cors doesn’t let me test it in localhost

---

<div class="post-metadata">

**Author:** ![bep](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/bep/32/3332_2.png) [@bep](https://discourse.gohugo.io/u/bep)\
**Post date:** [July 29, 2024, 9:34pm UTC](https://discourse.gohugo.io/t/dev-localhost-and-cors/4499/14 "2024-07-29T21:34:12Z")

</div>

See the -tls\* flags here:

> **[hugo server](https://gohugo.io/commands/hugo_server/#options)**
>
> hugo server A high performance webserver
> Synopsis Hugo provides its own webserver which builds and serves the site. While hugo server is high performance, it is a webserver with limited options.
> The hugo server command will by default write and serve...

You need to run

```auto
hugo server trust

```

First to install a local CA.
