AngularJS:阻止跨源请求:同源策略禁止读取远程资源

Mim*_*uni 15 apache angularjs

这是我的代码:

angular.module('option')
    .factory('optionListService', ['$resource', function($resource) {
    return $resource(HOST+'option/action/:id', {}, {
        'get':    {method:'GET'},
            'save':   {method:'POST'},
            'query':  {method:'GET', isArray:true},
            'remove': {method:'DELETE'},
            'delete': {method:'DELETE'}
    });
    }]);
Run Code Online (Sandbox Code Playgroud)

这适用于GET请求而不是POST!

我使用Apache作为服务器并配置它:

<Limit GET HEAD POST PUT DELETE OPTIONS>
        Order Allow,Deny
        Allow from all
    </Limit>
Header set Access-Control-Allow-Origin "*"
Run Code Online (Sandbox Code Playgroud)

在我的angularjs中,我包含在模块app的配置中:

delete $httpProvider.defaults.headers.common['X-Requested-With'];
delete $httpProvider.defaults.headers.post['Content-type'];
Run Code Online (Sandbox Code Playgroud)

但请求POST仍然无法正常工作!!

我希望有人可以提出任何想法.

Seb*_*ian 27

在服务器端添加这些标头:

Access-Control-Request-Headers: X-Requested-With, accept, content-type
Access-Control-Allow-Methods: GET, POST
Run Code Online (Sandbox Code Playgroud)

如果仍然无法发布OPTIONS浏览器正在发送的预检请求的详细信息.

为什么需要这个?

如果它不是简单的请求(例如表格数据的GET或POST),则浏览器向OPTIONS服务器发送预检HTTP 请求以检查是否允许CORS.此请求包含一些Access-Control-Request标头(可能因具体请求而异):

Access-Control-Request-Headers: accept, content-type
Access-Control-Request-Method: POST
Run Code Online (Sandbox Code Playgroud)

现在,服务器Access-Control-Allow在响应中引用相同的标头非常重要:

Access-Control-Allow-Headers: accept, content-type
Access-Control-Allow-Methods: POST
Access-Control-Allow-Origin: *
Run Code Online (Sandbox Code Playgroud)

否则,浏览器会拒绝该请求.

@ilyas:经过3个小时的研究后,我终于找到了这个问题

//Part added by ilyas :
    if (isset($_SERVER['HTTP_ORIGIN'])) {
        header("Access-Control-Allow-Origin: {$_SERVER['HTTP_ORIGIN']}");
        header('Access-Control-Allow-Credentials: true');
        header('Access-Control-Max-Age: 86400');    // cache for 1 day
    }
//End of part.
Run Code Online (Sandbox Code Playgroud)

我希望这有助于他人.

  • 您好,我应该在哪里放置这些访问控制标头? (2认同)