Skip to main content

Configuring CORS on S3 for ActiveStorage

Posted on

If you haven’t tried Rails new ActiveStorage feature, do it! It’s bloody lovely to work with! However, recently I ran into a “OMFG why isn’t this working” moment while uploading files with Direct Upload to AWS S3 via ActiveStorage in Ruby On Rails.

The Error

After submitting the form, it got stuck in it’s disabled “I am submitting” state.

The error in my browser console looked a little like this:

Access to XMLHttpRequest at '…Signature=3652b50…' from origin '' has been blocked by CORS policy: Response to preflight request doesn't pass access control check: No 'Access-Control-Allow-Origin' header is present on the requested resource.

The Fix

The fix took me a bit of searching to get this totally right, but on the AWS website navigate to your S3 bucket, go to permissions, then “CORS Configuration”. The URL should look something like:

From here, adjust your configuration to look like:

<?xml version="1.0" encoding="UTF-8"?>
<CORSConfiguration xmlns="">