What it means
A browser lets a page call only its own address, unless the other server says the page's origin is allowed. That permission is CORS. Your API did not allow the origin of your frontend, so the browser stopped the call. This is the browser protecting people, and the server decides what to allow.
How to fix it
-
Allow your frontend's exact origin on the API
An origin is the address without a path, for example
https://my-app.antideploy.app. Add it to the API's allowed origins. Add your own domain too, if you attach one. -
Do not use a wildcard for a private API
Access-Control-Allow-Origin: *lets any website call it. Antideploy's security check reports a wide-open CORS policy as a finding. -
Stop using
localhostin the frontendYour frontend must call the live API address. Read it from an environment variable, or use a relative path when both are on one address.
import cors from "cors";
app.use(cors({ origin: process.env.FRONTEND_ORIGIN }));
The simplest layout
If one server serves both your frontend and your API, they share one origin, and no CORS setup is needed. See how to deploy a full-stack app.