Nginx´î½¨Ð§ÀÍÆ÷µÄ¿çÓò»á¼ûÉèÖúÍCORSÐÒéÖ§³ÖÖ¸ÄÏ
nginx´î½¨Ð§ÀÍÆ÷µÄ¿çÓò»á¼ûÉèÖúÍcorsÐÒéÖ§³ÖÖ¸ÄÏ
СÐò£º
ÔÚÄ¿½ñµÄWebÓ¦Óÿª·¢ÖУ¬¿çÓòÇëÇóÒѾ³ÉΪһÖÖ³£¼ûµÄÐèÇó¡£ÎªÁË°ü¹ÜÇå¾²ÐÔ£¬ä¯ÀÀÆ÷ĬÈÏ»áÏÞÖÆͨ¹ýAJAXÇëÇó¾ÙÐеĿçÓò²Ù×÷¡£CORS£¨¿çÓò×ÊÔ´¹²Ïí£©ÐÒéΪ¿ª·¢ÕßÌṩÁËÒ»ÖÖ¿É¿¿µÄ½â¾ö¼Æ»®£¬¿ÉÒÔʵÏÖ¿çÓò»á¼ûµÄ¿É¿ØÊÚȨ¡£
NginxÊÇÒ»¸ö¸ßÐÔÄܵÄWebЧÀÍÆ÷ºÍ·´ÏòÊðÀíЧÀÍÆ÷£¬±¾ÎĽ«ÏÈÈÝÔõÑùʹÓÃNginxÀ´´î½¨Ð§ÀÍÆ÷µÄ¿çÓò»á¼ûÉèÖúÍCORSÐÒéÖ§³Ö¡£
ÉèÖÃЧÀÍÆ÷µÄ¿çÓò»á¼û
ΪÁËÊÚȨÆäËûÓòÃûµÄ»á¼û£¬ÎÒÃÇÊ×ÏÈÐèÒªÔÚNginxµÄÉèÖÃÎļþÖÐÌí¼Ó¿çÓò»á¼ûÉèÖ᣷¿ªNginxµÄÉèÖÃÎļþ£¨Í¨³£ÊÇ/etc/nginx/nginx.conf£©£¬ÔÚhttp²¿·ÖÌí¼ÓÒÔÏÂÉèÖãº
http { ... # ÔÊÐí¿çÓò»á¼û add_header Access-Control-Allow-Origin *; add_header Access-Control-Allow-Methods 'GET, POST, OPTIONS'; add_header Access-Control-Allow-Headers 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; add_header Access-Control-Expose-Headers 'Content-Length,Content-Range'; }
µÇ¼ºó¸´ÖÆ
ÉÏÊöÉèÖÃÔÊÐíËùÓÐÓòÃû£¨*£©¾ÙÐлá¼û£¬²¢ÇÒÖ§³ÖGET¡¢POST¡¢OPTIONSÒªÁ졣ͬʱ£¬ÎÒÃÇ»¹Ö¸¶¨ÁËһЩ³£¼ûµÄÇëÇóÍ·ÐÅÏ¢¡£
ÔÚÉúÑIJ¢Í˳öÉèÖÃÎļþºó£¬ÖØмÓÔØNginxÉèÖÃʹÆäÉúЧ£º
$ sudo nginx -s reload
µÇ¼ºó¸´ÖÆ
ÉèÖÃCORSÐÒéÖ§³Ö
ÔÚЧÀÍÆ÷ÖÐÌí¼Ó¿çÓò»á¼ûÉèÖúó£¬ÎÒÃÇ»¹¿ÉÒÔ¸üϸÁ£¶ÈµØÉèÖÃCORSÐÒéµÄÖ§³Ö¡£ÒÔÏÂÊÇÒ»¸öʾÀýÉèÖã¬Ö»ÔÊÐíÖ¸¶¨ÓòÃû¾ÙÐпçÓò»á¼û£º
http { ... # ÉèÖÃCORS map $http_origin $allowed_origin { default ""; ~^https?://(www.)?example.com$ $http_origin; ~^https?://(www.)?example.net$ $http_origin; } server { ... location / { if ($allowed_origin != "") { add_header 'Access-Control-Allow-Origin' $allowed_origin; add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range'; } ... } } }
µÇ¼ºó¸´ÖÆ
ÉÏÊöÉèÖÃÖУ¬ÎÒÃÇʹÓÃÁËmapÖ¸ÁîÀ´½ç˵һ¸ö$allowed_origin±äÁ¿£¬ÓÃÓÚ´æ´¢ÔÊÐí¿çÓò»á¼ûµÄÓòÃû¡£ÔÚserver¿éÖÐÉèÖÃÁËlocation /£¬²¢Í¨¹ýifÖ¸ÁîÅжÏÄ¿½ñÇëÇóȪԴµÄÓòÃûÊÇ·ñÔÚÔÊÐíÁбíÖС£ÈôÊÇÊÇ£¬ÔòÌí¼ÓÏìÓ¦µÄCORSÍ·ÐÅÏ¢¡£±ðµÄ£¬ÎÒÃÇÒ²¿ÉÒÔƾ֤×Ô¼ºµÄÐèÒªÌí¼Ó¸ü¶àµÄ¹æÔò¡£
CORSÇëÇóµÄÔ¤¼ì£¨preflight£©
ÔÚijЩÇéÐÎÏ£¬¿çÓòÇëÇóÐèÒª¾ÙÐÐÔ¤¼ì²Ù×÷¡£ÀýÈçʹÓÃÁË×Ô½ç˵µÄÇëÇóÍ·ÐÅÏ¢»ò·Ç¼òÆÓÇëÇó£¨ÀýÈçPUT¡¢DELETEµÈ£©Ê±¡£Ô¤¼ìÇëÇóÊÇÔÚÏÖʵÇëÇó֮ǰ·¢Ë͵ÄÒ»ÖÖOPTIONSÇëÇó£¬ÓÃÓÚ»ñȡЧÀÍÆ÷¶ÔÏÖʵÇëÇóµÄÊÚȨ¡£
ΪÁËÖ§³ÖÔ¤¼ìÇëÇó£¬ÎÒÃÇÖ»ÐèÒªÔÚlocation /¿éÖÐÌí¼ÓÒÔÏÂÉèÖü´¿É£º
location / { ... if ($request_method = 'OPTIONS') { add_header 'Access-Control-Allow-Origin' $allowed_origin; add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range'; return 204; } ... }
µÇ¼ºó¸´ÖÆ
ÉÏÊöÉèÖÃÖУ¬µ±ÇëÇóÒªÁìΪOPTIONSʱ£¬ÎÒÃÇ·µ»Ø204£¨No Content£©²¢Ìí¼ÓCORSÍ·ÐÅÏ¢¡£
½áÂÛ£º
ͨ¹ýÉÏÊöÉèÖã¬ÎÒÃÇ¿ÉÒÔÇáËɵشЧÀÍÆ÷µÄ¿çÓò»á¼ûÉèÖúÍCORSÐÒéÖ§³Ö¡£ÎÞÂÛÊǼòÆӵĿçÓòÇëÇó£¬ÕÕ¾ÉÖØ´óµÄÔ¤¼ìÇëÇó£¬Nginx¶¼¿ÉÒÔÌṩÎÞаºÍ¿É¿¿µÄ½â¾ö¼Æ»®¡£
²Î¿¼ÎÄÏ×£º
[Nginx¹Ù·½Îĵµ](https://nginx.org/en/docs/)
[CORS¹Ù·½Îĵµ](https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS)
ÒÔÉϾÍÊÇNginx´î½¨Ð§ÀÍÆ÷µÄ¿çÓò»á¼ûÉèÖúÍCORSÐÒéÖ§³ÖÖ¸ÄϵÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡