Cannot remove response headers (Access-Control-Allow-Origin)

Hi Andrew,

Please see my comment inline.

The error you received is usually due to enabling CORS when the upstream is already adding the header, so it gets added twice.

[Toan] Sure. That’s reason that I want to remove 1 header value. I’m enabling CORS is because I cannot add my custom header into the request (version and apikey header name as you saw in above picture) if I don’t enable TYK CORS.

We couldn’t reproduce your second problem on our end, however, and we were able to add/remove CORS headers and add/remove Headers from endpoints using the endpoint designer. Can you confirm that this is still an issue for you?

[Toan] Yes, I still face the issue. Also I sent my tyk cloud account to your tyk message inbox so that you can help me access my API detail to double check that my API config is correct.

Would it be helpful if we organise a short call with one of our consulting engineers to better understand your use-case and plans for Tyk?

[Toan] Sure. I’m fine. Thanks for your supports.

Thanks,
Toan Do