Frontend: Angular application living in NGINX

Backend: java application living in Tomcat 8.5

The frontend needs to call backend Rest API. As far as I understand I need to allow CORS for this to happen:

so I went through Tomcat documentation and I added the cors filter to web.xml:


Then I restarted tomcat service

This setup is not working as expected:

$ curl -v \
> -H 'Accept: */*' \
> -H 'Accept-Encoding:gzip, deflate' \
> -H 'Accept-Language:en-US,en;q=0.9,es;q=0.8' \
> -H 'Access-Control-Request-Headers:authorization,content-type' \
> -H 'Access-Control-Request-Method:POST' \
> -H 'Connection:keep-alive' \
> -H 'Origin:http://dev.retex.global' \
> -H 'Host:dev.retex.global:8080' \
> http://dev.retex.global:8080/returnitRest/rest/pickup/label
* timeout on name lookup is not supported
*   Trying
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0* Connected to dev.retex.global ( port 8080 (#0)
> OPTIONS /returnitRest/rest/pickup/label HTTP/1.1
> Host:dev.retex.global:8080
> User-Agent: curl/7.47.1
> Accept: */*
> Accept-Encoding:gzip, deflate
> Accept-Language:en-US,en;q=0.9,es;q=0.8
> Access-Control-Request-Headers:authorization,content-type
> Access-Control-Request-Method:POST
> Connection:keep-alive
> Origin:http://dev.retex.global
< HTTP/1.1 403
< Content-Type: text/plain
< Content-Length: 0
< Date: Mon, 20 Nov 2017 09:54:22 GMT
  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
* Connection #0 to host dev.retex.global left intact

QUESTION: What am I doing wrong?

This is what I did to solve this issue:


