【发布时间】:2021-01-20 17:55:04
【问题描述】:
我正在尝试向我的 Golang AppEngine API 发送 fetch POST 请求。但是,我收到了 CORS 策略错误,我不知道为什么。这是我的代码:
这是从 Angular 调用 API 的代码
private async sendHTTPPut(data: UserInfo, func: string) {
let requestHeaders = { 'Content-Type': 'application/json', 'Access-Control-Allow-Origin': '*' } as HeadersInit;
console.log(requestHeaders)
return await fetch(
this.endpoint + func,
{
method: 'POST',
headers: requestHeaders,
body: JSON.stringify(data),
mode: "cors"
}
)
}
这是处理 CORS 的服务器代码:
func StartApp() {
router = mux.NewRouter()
router.HandleFunc("/", hello)
router.HandleFunc("/hello", hello)
router.HandleFunc("/AcceptMember", AcceptMember)
router.HandleFunc("/CreateTeam", CreateTeam)
router.HandleFunc("/Leave", Leave)
router.HandleFunc("/InviteMember", InviteMember)
router.HandleFunc("/BeginSignup", BeginSignup)
router.HandleFunc("/ProcessSignup", ProcessSignup)
router.HandleFunc("/CompleteSignup", CompleteSignup)
// Scoring
router.HandleFunc("/GetLocalScore", GetLocalScore)
allowedOrigins := handlers.AllowedOrigins([]string { "* always" })
allowedHeaders := handlers.AllowedHeaders([]string { "Content-Type" })
if err := http.ListenAndServe(":8080", handlers.CORS(allowedOrigins, allowedHeaders)(router)); err != nil {
log.Fatal(err)
}
}
这是发送到服务器的请求:
Request URL: http://localhost:8080/BeginSignup
Referrer Policy: no-referrer-when-downgrade
Provisional headers are shown
Access-Control-Allow-Origin: *
Content-Type: application/json
Referer: http://localhost:4200/
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36 Edg/85.0.564.68
PAYLOAD
{member: {phoneNum: "0648503047"},…}
member: {phoneNum: "0648503047"}
score: null
team: {teamName: ".None", teamMembers: ["0648503047"], teamLeader: "0648503047"}
这是从服务器发回的响应:
Request URL: http://localhost:8080/BeginSignup
Request Method: OPTIONS
Status Code: 200 OK
Remote Address: [::1]:8080
Referrer Policy: no-referrer-when-downgrade
Content-Length: 0
Date: Mon, 05 Oct 2020 20:34:51 GMT
Accept: */*
Accept-Encoding: gzip, deflate, br
Accept-Language: en-US,en;q=0.9
Access-Control-Request-Headers: access-control-allow-origin,content-type
Access-Control-Request-Method: POST
Connection: keep-alive
Host: localhost:8080
Origin: http://localhost:4200
Referer: http://localhost:4200/
Sec-Fetch-Dest: empty
Sec-Fetch-Mode: cors
Sec-Fetch-Site: same-site
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36 Edg/85.0.564.68
【问题讨论】:
-
Access-Control-Allow-Origin是响应头,不是请求头。 -
按照@HereticMonkey 所说的,这意味着它需要在服务器上定义,而不是在您的前端。
-
我在您的服务器响应中缺少 allow-origin CORS 标头。考虑到这是一个 OPTIONS 预检响应,Access-Control-Request-Method: POST 似乎也很奇怪..
-
我现在将其更改为选项。不确定为什么缺少允许来源?仍有 CORS 问题
标签: angular typescript http go cors