01Inspect OPTIONS and POST separately
Record status and headers for the preflight and the actual invocation.
What the result tells you: A failed OPTIONS request is an origin/header/method contract problem, not application logic.
Appears when: Edge Function CORS or 500
CORS and 500 errors are different layers. A browser CORS failure means the response does not permit the origin or preflight; a 500 means the function executed and failed. Inspect the OPTIONS request, function logs, production secrets, and upstream response separately.
# Choose the allowed originsList the controlled production and development origins that may invoke the function.# Return consistent CORS headersHandle OPTIONS and include matching headers on success and error responses.# Repair the first 500 causeAdd the missing secret, validation, timeout, or upstream error handling proved by logs.# Test preflight, success, and failureVerify allowed and disallowed origins plus a controlled dependency failure.Preserve the current working revision, change one proven boundary, and verify the published path in a clean session.
Record status and headers for the preflight and the actual invocation.
What the result tells you: A failed OPTIONS request is an origin/header/method contract problem, not application logic.
Use the timestamp and request id for the exact failing invocation.
What the result tells you: A 500 with a stack trace moves diagnosis to code, missing secrets, parsing, or an upstream dependency.
Verify the live Lovable domain, authorization header, content type, and method are deliberately allowed.
What the result tells you: Preview may work because it uses a different origin or request shape.
| Likely cause | What proves it | First safe action |
|---|---|---|
| OPTIONS is not handled | A failed OPTIONS request is an origin/header/method contract problem, not application logic. | Choose the allowed origins |
| Allowed origin is wrong | A 500 with a stack trace moves diagnosis to code, missing secrets, parsing, or an upstream dependency. | Return consistent CORS headers |
| Missing function secret | Preview may work because it uses a different origin or request shape. | Repair the first 500 cause |
| Unhandled upstream failure | A failed OPTIONS request is an origin/header/method contract problem, not application logic. | Test preflight, success, and failure |
CORS and 500 errors are different layers. A browser CORS failure means the response does not permit the origin or preflight; a 500 means the function executed and failed. Inspect the OPTIONS request, function logs, production secrets, and upstream response separately.
The function executes only the business request and never returns preflight headers.
Headers cover preview or localhost but not the published domain.
The deployed function cannot reach an API or database dependency.
Freeze generated changes, restore the last known working version, reproduce one request, collect the browser and platform logs, and change one layer at a time.
It may hide an origin mismatch but is not appropriate for every production or credentialed request. Allow only the origins the product requires.
Server-side and dashboard tests are not subject to the browser’s CORS enforcement.
They can appear together, but diagnose them separately: CORS concerns browser permission; 500 concerns function execution.
Free decision aid
Get a senior view of the constraint, the evidence you have, and the next decision that removes the most risk.
No email required for this decision aid. Dismiss once and this popup stays closed for the session.