Fortinet white logo
Fortinet white logo

Administration Guide

OPTIONS Requests Bypass Authentication (8.0.3)

OPTIONS Requests Bypass Authentication (8.0.3)

FortiWeb 8.0.3 now automatically allows HTTP OPTIONS requests to bypass authentication checks. This behavior aligns with CORS standards (W3C Fetch) and common security best practices, where OPTIONS requests are used for browser-initiated preflight checks and are not intended to carry credentials or trigger authentication logic.

By excluding OPTIONS requests from authentication processing, FortiWeb improves compatibility with modern web applications and prevents unnecessary authentication failures during cross-origin requests.

OPTIONS Requests Bypass Authentication (8.0.3)

OPTIONS Requests Bypass Authentication (8.0.3)

FortiWeb 8.0.3 now automatically allows HTTP OPTIONS requests to bypass authentication checks. This behavior aligns with CORS standards (W3C Fetch) and common security best practices, where OPTIONS requests are used for browser-initiated preflight checks and are not intended to carry credentials or trigger authentication logic.

By excluding OPTIONS requests from authentication processing, FortiWeb improves compatibility with modern web applications and prevents unnecessary authentication failures during cross-origin requests.