Symptom
You are attempting to configure single sign on (SSO) to SAP HANA's Information Access (InA) service from SAP Analytics Cloud (SAC) as a part of the Live Data Connection to SAP HANA scenario.
- As per SameSite Cookie Configuration for Live Data Connections, you have created a rewrite rule to ensure that your cookies are CORS ready
- As per Configure Cross-Origin Resource Sharing (CORS) support on your SAP HANA system you have set the CORS policy for application object sap.bc.ina.service.v2 such that your SAP Analytics Cloud origin is allowed
However, when you test your SSO authentication you see messages similar to the following in your web browser's console (Ctrl+Shift+J Chromium; Ctrl+Shift+K FireFox; etc.):
"Access to XMLHttpRequest at '<IdP endpoint>' (redirected from 'https://<SAP HANA hostname>:43<NR>/sap/bc/ina/service/v2/GetServerInfo') from origin 'https://<customer specific subdomain>.sapanalytics.cloud' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource."
Read more...
Environment
SAP HANA, platform edition
Product
Keywords
Microsoft, Okta, cross, origin, resource, sharing, Response to preflight request doesn't pass access control check , KBA , HAN-DB-SEC , SAP HANA Security & User Management , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.