# How to use Nginx web server for reverse proxy between ASP.NET web app and Orthanc server?

**URL:** https://discourse.orthanc-server.org/t/how-to-use-nginx-web-server-for-reverse-proxy-between-asp-net-web-app-and-orthanc-server/426
**Category:** Google Groups archive
**Created:** [May 19, 2016, 4:50am UTC](https://discourse.orthanc-server.org/t/how-to-use-nginx-web-server-for-reverse-proxy-between-asp-net-web-app-and-orthanc-server/426 "2016-05-19T04:50:55Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Si\_Thu\_Kyaw](https://discourse.orthanc-server.org/letter_avatar_proxy/v4/letter/s/91b2a8/32.png) [@Si\_Thu\_Kyaw](https://discourse.orthanc-server.org/u/Si_Thu_Kyaw)
#### Post date: [May 19, 2016, 4:50am UTC](https://discourse.orthanc-server.org/t/how-to-use-nginx-web-server-for-reverse-proxy-between-asp-net-web-app-and-orthanc-server/426/1 "2016-05-19T04:50:55Z")

</div>

I am trying to use Orthanc (open-source) dicom server to manage my dicom files. I have an [ASP.NET](http://ASP.NET) MVC 5 application that contains Cornerstone (Dicom Viewer) javascript library to load and view the dicom files from Orthanc’s Web API.

The problem is whenever the Cornerstone javascript library make XHR request to Orthanc server, the Cross Origin Resource Sharing related error. i.e; “No ‘Access-Control-Allow-Origin’ header is present on the requested resource” occurs.

As in the Orthanc offical documentation, I found that one of the ways to resolve the CROS problem is setting up an reverse proxy server. So, I install Nginx server.

The expected request processes are as follow;

- [ASP.NET](http://ASP.NET) MVC client at localhost:33488/index.html makes XMLHttpRequest to Proxy Server Listening at localhost port 8082
- The proxy server then passes the request to the Orthanc Web API at localhost:8042/ with require CORS headers

but it is still couldn’t resolve the CORS problem.

[![](https://lh3.googleusercontent.com/-rfyRVULURX8/Vz1GC_jwHrI/AAAAAAAAAAg/AOmYDkZYaPQgFOM0ShnQrZL76pkwbHG1ACLcB/s320/For_stackoverflow.png)](https://lh3.googleusercontent.com/-rfyRVULURX8/Vz1GC_jwHrI/AAAAAAAAAAg/AOmYDkZYaPQgFOM0ShnQrZL76pkwbHG1ACLcB/s1600/For_stackoverflow.png)

This is my Nginx proxy server configurations.

---

<div class="post-metadata">

### Author: ![Alain\_Mazy3](https://discourse.orthanc-server.org/letter_avatar_proxy/v4/letter/a/eb9ed0/32.png) [@Alain\_Mazy3](https://discourse.orthanc-server.org/u/Alain_Mazy3)
#### Post date: [May 19, 2016, 5:23am UTC](https://discourse.orthanc-server.org/t/how-to-use-nginx-web-server-for-reverse-proxy-between-asp-net-web-app-and-orthanc-server/426/2 "2016-05-19T05:23:53Z")

</div>

To avoid the CORS problems, your orthanc server and your [ASP.Net](http://ASP.Net) application should be available on the same port.

Here, you still have your [ASP.Net](http://ASP.Net) app on port 80 and your orthanc app on port 8082.  
I think you should also configure a reverse proxy for your [ASP.Net](http://ASP.Net) app so the they are both on the same port.

Your app should use ‘/instances’ as the base url for orthanc and not ‘[http://localhost:8082/instances](http://localhost:8082/instances)’

Here is a sample nginx config we use with a django app served on port 9750:

server {

listen 80;

# server\_name [example.org](http://example.org);

charset utf-8;

root /var/www/apps/webApp; #the static files

location / {  
}

location /api/ { #the django app  
proxy\_pass [http://127.0.0.1:9750](http://127.0.0.1:9750);  
rewrite /api(.\*) /$1 break;  
}

location /orthanc { #the orthanc app  
rewrite /orthanc(.\*) /$1 break;  
proxy\_pass [http://127.0.0.1:8042](http://127.0.0.1:8042);  
proxy\_set\_header Host $host;  
proxy\_set\_header X-Real-IP $remote\_addr;  
proxy\_set\_header X-Forwarded-For $proxy\_add\_x\_forwarded\_for;  
}  
}

---

<div class="post-metadata">

### Author: ![Si\_Thu\_Kyaw](https://discourse.orthanc-server.org/letter_avatar_proxy/v4/letter/s/91b2a8/32.png) [@Si\_Thu\_Kyaw](https://discourse.orthanc-server.org/u/Si_Thu_Kyaw)
#### Post date: [May 19, 2016, 5:47am UTC](https://discourse.orthanc-server.org/t/how-to-use-nginx-web-server-for-reverse-proxy-between-asp-net-web-app-and-orthanc-server/426/3 "2016-05-19T05:47:55Z")

</div>

> Thank you Alain Mazy,

Thanks for the useful information. I am going back to project to test the way you advice. 🙂

---

<div class="post-metadata">

### Author: ![Si\_Thu\_Kyaw](https://discourse.orthanc-server.org/letter_avatar_proxy/v4/letter/s/91b2a8/32.png) [@Si\_Thu\_Kyaw](https://discourse.orthanc-server.org/u/Si_Thu_Kyaw)
#### Post date: [May 19, 2016, 7:54am UTC](https://discourse.orthanc-server.org/t/how-to-use-nginx-web-server-for-reverse-proxy-between-asp-net-web-app-and-orthanc-server/426/4 "2016-05-19T07:54:35Z")

</div>

I updated the Ngnix proxy server configuration and everything is currently working fine for local server but I haven’t tasted for remotely hosted servers.  
I didn’t change anything for CORS support in IIS and my [Asp.Net](http://Asp.Net) MVC application config.

The updated Ngnix’s config file (nginx.conf) was as follow;

`  
#proxy-server  
server {

listen 8082;  
server\_name default\_server;

location /orthanc/{  
access\_log logs/access.log;  
proxy\_pass [http://localhost:8042](http://localhost:8042);  
proxy\_set\_header HOST $host;  
proxy\_set\_header X-Real-IP $remote\_addr;  
rewrite /orthanc(.\*) $1 break;

add\_header ‘Access-Control-Allow-Credentials’ ‘true’;  
add\_header ‘Access-Control-Allow-Headers’ ‘DNT,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type’;  
add\_header ‘Access-Control-Allow-Methods’ ‘GET, POST, OPTIONS’;  
add\_header ‘Access-Control-Allow-Origin’ ‘\*’;

}

}  
`

The XHR request from the Cornerstone library is like this:  
`http://localhost:8082/orthanc/instances/d0630585-b29faf47-cf580bcc-31268167-b557b3c9/file;`

Now it works as expected, the Nginx proxy server was updated the required CORS header information and passed to Orthanc REST API. Then Orthanc server now response with required dicom file.

[![](https://lh3.googleusercontent.com/-l_FRa_Cc-0A/Vz1wpcgElaI/AAAAAAAAAAw/NW12sSRr8Wg_9OGgRiz8_IZPTWnJbH4lQCLcB/s320/CORS_Success.png)](https://lh3.googleusercontent.com/-l_FRa_Cc-0A/Vz1wpcgElaI/AAAAAAAAAAw/NW12sSRr8Wg_9OGgRiz8_IZPTWnJbH4lQCLcB/s1600/CORS_Success.png)
