# Headers are not applied

**URL:** <https://community.traefik.io/t/headers-are-not-applied/16958>\
**Category:** Traefik v2\
**Tags:** docker, middleware\
**Created:** [December 30, 2022, 9:45am UTC](https://community.traefik.io/t/headers-are-not-applied/16958 "2022-12-30T09:45:03Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shidooo](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/shidooo/32/3324_2.png) [@Shidooo](https://community.traefik.io/u/Shidooo)\
**Post date:** [December 30, 2022, 9:45am UTC](https://community.traefik.io/t/headers-are-not-applied/16958/1 "2022-12-30T09:45:04Z")

</div>

Hello, my headers are not applied but the dashboard is seems correct.

```auto
services:
  traefik:
    image: traefik:v2.7
    .........
    labels:
      - traefik.enable=true
     .......
      - traefik.http.middlewares.headers.headers.frameDeny=true
      - traefik.http.middlewares.headers.headers.browserXssFilter=true
      - traefik.http.middlewares.headers.headers.stsIncludeSubdomains=true
      - traefik.http.middlewares.headers.headers.forceSTSHeader=true
      - traefik.http.middlewares.headers.headers.contentSecurityPolicy=true
      - traefik.http.middlewares.headers.headers.accessControlAllowOriginList=https://mydomain.com
      - traefik.http.middlewares.headers.headers.accessControlAllowCredentials=true
    .......
    networks:
      - traefik-network

frontend:
    ...........
    labels:
      - traefik.enable=true
      .......
      - traefik.http.routers.frontend.middlewares=headers
    networks:
      - traefik-network

```

 ![Screenshot_1](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/0/076141ee45af143fddd49581f54c001639b55fb7.png)

It seems that there are only a few that work (Access-control-allow-credentials: true)

By using online header checkers or checking by myself, headers seems not to be applied. I should see mydomain as CORS origin...

![Screenshot_2](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/b/bb817ff409ec22035ecbef0b565b28739684a119.png)

Thanks for helping

---

<div class="post-metadata">

**Author:** ![douglasdtm](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/douglasdtm/32/2002_2.png) [@douglasdtm](https://community.traefik.io/u/douglasdtm)\
**Post date:** [December 30, 2022, 12:43pm UTC](https://community.traefik.io/t/headers-are-not-applied/16958/2 "2022-12-30T12:43:42Z")

</div>

@Shidooo does the Origin header in the request matches the AllowOriginList?  
[https://mydomain.com](https://mydomain.com) in this case

---

<div class="post-metadata">

**Author:** ![Shidooo](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/shidooo/32/3324_2.png) [@Shidooo](https://community.traefik.io/u/Shidooo)\
**Post date:** [December 30, 2022, 4:17pm UTC](https://community.traefik.io/t/headers-are-not-applied/16958/3 "2022-12-30T16:17:32Z")

</div>

@douglasdtm

my backend and frontend are both on the same origin [https://mydomain.com](https://mydomain.com)  
and traefik is on [https://traefik.mydomain.com](https://traefik.mydomain.com)  
all on the same server

Does this answer your question? 😄

---

<div class="post-metadata">

**Author:** ![Shidooo](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/shidooo/32/3324_2.png) [@Shidooo](https://community.traefik.io/u/Shidooo)\
**Post date:** [January 4, 2023, 12:44pm UTC](https://community.traefik.io/t/headers-are-not-applied/16958/4 "2023-01-04T12:44:40Z")

</div>

I still haven't found a solution, I tried to update traefik to version 3.0, the problem still exists.

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [January 4, 2023, 4:04pm UTC](https://community.traefik.io/t/headers-are-not-applied/16958/5 "2023-01-04T16:04:07Z")

</div>

> [@Shidooo](#):
>
> `traefik.http.routers.frontend.middlewares=headers`

Have you tried adding `@docker` at the end? As the middleware is defined by `provider.docker` through the labels.

---

<div class="post-metadata">

**Author:** ![Shidooo](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/shidooo/32/3324_2.png) [@Shidooo](https://community.traefik.io/u/Shidooo)\
**Post date:** [January 6, 2023, 9:03am UTC](https://community.traefik.io/t/headers-are-not-applied/16958/6 "2023-01-06T09:03:21Z")

</div>

This does not seem to have changed. I still have some of my headers that don't show up as "accessControlAllowOriginList".

---

<div class="post-metadata">

**Author:** ![Shidooo](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/shidooo/32/3324_2.png) [@Shidooo](https://community.traefik.io/u/Shidooo)\
**Post date:** [January 6, 2023, 9:07am UTC](https://community.traefik.io/t/headers-are-not-applied/16958/7 "2023-01-06T09:07:45Z")

</div>

I believe that only the headers that are already generated by my services are propagated. But the ones I want to add through traefik are not added at all. Even if the interface indicates otherwise.

Any idea ?

 ![Screenshot_4](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/5/52971994555f60287474430d2d7bc0033fa16536.png)

---

<div class="post-metadata">

**Author:** ![Shidooo](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/shidooo/32/3324_2.png) [@Shidooo](https://community.traefik.io/u/Shidooo)\
**Post date:** [January 21, 2023, 8:45pm UTC](https://community.traefik.io/t/headers-are-not-applied/16958/8 "2023-01-21T20:45:28Z")

</div>

It's still not working.

---

<div class="post-metadata">

**Author:** ![rtribotte](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/rtribotte/32/1966_2.png) [@rtribotte](https://community.traefik.io/u/rtribotte)\
**Post date:** [January 23, 2023, 3:15pm UTC](https://community.traefik.io/t/headers-are-not-applied/16958/9 "2023-01-23T15:15:39Z")

</div>

Hello @Shidooo,

Configuration-wise, everything seems ok.

> my backend and frontend are both on the same origin [https://mydomain.com](https://mydomain.com/)  
> and traefik is on [https://traefik.mydomain.com](https://traefik.mydomain.com/) all on the same server  
> Does this answer your question? 😄

Well, I fear that this is not really answering the question 😉  
I think @douglasdtm wanted to ask you if you did make sure that the request has the `Origin` header set to the correct value, can you double-check that?  
Thanks!

---

<div class="post-metadata">

**Author:** ![thanawat](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/thanawat/32/6592_2.png) [@thanawat](https://community.traefik.io/u/thanawat)\
**Post date:** [February 1, 2023, 3:23pm UTC](https://community.traefik.io/t/headers-are-not-applied/16958/10 "2023-02-01T15:23:12Z")

</div>

I have problems as same as you. I try to upgrade the version but all problems still not working too.

 ![Untitled](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/2/21e9b341a6fba98cb4e8df9f7ba28d2c613dab47.png)

Hello @ [rtribotte](https://community.traefik.io/u/rtribotte)

> I think @douglasdtm wanted to ask you if you did make sure that the request has the `Origin` header set to the correct value, can you double-check that?

I double-checked the request with many different values all problems still not working.

---

<div class="post-metadata">

**Author:** ![thanawat](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/thanawat/32/6592_2.png) [@thanawat](https://community.traefik.io/u/thanawat)\
**Post date:** [February 2, 2023, 7:40am UTC](https://community.traefik.io/t/headers-are-not-applied/16958/11 "2023-02-02T07:40:01Z")

</div>

I switch to using `customResponseHeaders` - (ref.: [docs](https://doc.traefik.io/traefik/middlewares/http/headers/#customresponseheaders)) option like

```auto
...
- traefik.http.middlewares.cors.headers.customResponseHeaders.access-control-allow-origin=https://example.com
- traefik.http.middlewares.cors.headers.customResponseHeaders.access-control-allow-credentials=true
...

```

But this solution only supports one domain I hope will support soon.

---

<div class="post-metadata">

**Author:** ![LugaLee](https://avatars.discourse-cdn.com/v4/letter/l/f07891/32.png) [@LugaLee](https://community.traefik.io/u/LugaLee)\
**Post date:** [September 20, 2023, 3:20am UTC](https://community.traefik.io/t/headers-are-not-applied/16958/12 "2023-09-20T03:20:18Z")

</div>

Hi，Has this issue been resolved?

---

<div class="post-metadata">

**Author:** ![Mike-the-one](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/mike-the-one/32/3174_2.png) [@Mike-the-one](https://community.traefik.io/u/Mike-the-one)\
**Post date:** [May 18, 2024, 10:03am UTC](https://community.traefik.io/t/headers-are-not-applied/16958/13 "2024-05-18T10:03:16Z")

</div>

I am having the same problem! Any ideas?

---

<div class="post-metadata">

**Author:** ![Mike-the-one](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/mike-the-one/32/3174_2.png) [@Mike-the-one](https://community.traefik.io/u/Mike-the-one)\
**Post date:** [May 18, 2024, 10:04am UTC](https://community.traefik.io/t/headers-are-not-applied/16958/14 "2024-05-18T10:04:40Z")

</div>

> [@thanawat](#):
>
> `customResponseHeaders`

customResponseHeaders also doesn't work for me

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [May 21, 2024, 7:46am UTC](https://community.traefik.io/t/headers-are-not-applied/16958/15 "2024-05-21T07:46:28Z")

</div>

Works for me.

RequestHeader added to request, ResponseHeader added to response.

You need to declare and assign the headers ([doc](https://doc.traefik.io/traefik/middlewares/http/headers/)):

```auto
#docker-compose.yml
services:
  traefik:
    image: traefik:v2.11
    ports:
      - 80:80
    networks:
      - proxy
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro
    command:
      - --providers.docker=true
      - --providers.docker.exposedByDefault=false
      - --entryPoints.web.address=:80
      #- --log.level=DEBUG
      - --accesslog=true
      #- --accesslog.format=json

  whoami:
    image: traefik/whoami:v1.10
    networks:
      - proxy
    labels:
      - traefik.enable=true
      - traefik.http.routers.whoami.rule=Host(`whoami.example.com`)
      - traefik.http.middlewares.myRequestHeader.headers.customrequestheaders.X-myRequestHeader=FOO
      - traefik.http.middlewares.myResponseHeader.headers.customresponseheaders.X-myResponseHeader=BAR
      - traefik.http.routers.whoami.middlewares=myRequestHeader,myResponseHeader
      - traefik.http.services.whoami.loadbalancer.server.port=80

networks:
  proxy:
    name: proxy

```
