【问题标题】:CORS failure in with Python Falcon even with heads for Auth Pre-FlightPython Falcon 的 CORS 失败,即使是 Auth Pre-Flight 的负责人
【发布时间】:2017-07-31 14:21:58
【问题描述】:

在 Angular2 http.get(url, options) 中使用 OPTIONS 动词 时收到这些错误,即使在 Falcon Rest API 中设置了适当的 CORS 标头。

XMLHttpRequest 无法加载 http://localhost:8000/names。请求头 Access-Control-Allow-Headers 不允许字段授权 预检响应。

resp.set_header("Access-Control-Allow-Origin", "*")
        resp.set_header("Access-Control-Allow-Credentials", "true")
        resp.set_header("Access-Control-Allow-Methods", "GET,HEAD,OPTIONS,POST,PUT")
        resp.set_header("Access-Control-Allow-Headers",
                       "Access-Control-Allow-Headers, Origin,Accept, X-Requested-With, Content-Type, Access-Control-Request-Method, Access-Control-Request-Headers")

对于非 OPTIONS / 正常的 http.get() 请求,这可以正常工作。

【问题讨论】:

  • 看起来这些来自 Angular 的 OPTIONS 请求需要由 falcon 适当处理? stackoverflow.com/questions/6660019/…
  • 对我来说同样的问题。我必须将 allow_origins_listallow_all_methodsallow_all_headers 的全部设置为 True

标签: python angular typescript auth0 falcon


【解决方案1】:

使用 falcon_cors 解决了这个问题,特别是通过设置 allow_all_methods=True

pip install falcon-cors

from falcon_cors import CORS

cors = CORS(allow_origins_list=['http://localhost:3000'],
            allow_all_headers=True,
            allow_all_methods=True)

api = falcon.API(middleware=[cors.middleware])

【讨论】:

【解决方案2】:

我按照by lwcolton on github here的指导尝试了

同时设置allow_all_headers=True, allow_all_methods=True

即类似于上面的答案https://stackoverflow.com/a/42716126/248616,但还要添加两个参数

from falcon_cors import CORS

cors = CORS(
    allow_all_origins=True,
    allow_all_headers=True,
    allow_all_methods=True,
)

api = falcon.API(middleware=[cors.middleware])

【讨论】:

    【解决方案3】:

    我建议通过documentation 处理这个。

    另外,resp.set_header('Access-Control-Allow-Origin', '*') 不是在生产中遵循的好习惯。有一些列入白名单的来源和方法,并根据请求,如果来自列入白名单的来源,那么您可以在此处输入相同的来源resp.set_header('Access-Control-Allow-Origin', req.headers["ORIGIN"])

    下面是我喜欢的代码-

    whitelisted_origins = ["http://localhost:4200"]
    whitelisted_methods = ["GET", "POST", "OPTIONS"]
    
    class CORSComponent:
    
        def process_request(self, req, resp):
            success = False
            # validate request origin
            if ("ORIGIN" in req.headers):
                # validate request origin
                if (req.headers["ORIGIN"] in whitelisted_origins):
                    # validate request method
                    if (req.method in whitelisted_methods):
                        success = True
                    else:
                        # you can put required resp.status and resp.media here
                        pass
                else:
                    # you can put required resp.status and resp.media here
                    pass
            else:
                # you can put required resp.status and resp.media here
                pass
            if success:
                resp.set_header('Access-Control-Allow-Origin', req.headers["ORIGIN"])
            else:
                # exit request
                resp.complete = True
    
        def process_response(self, req, resp, resource, req_succeeded):
            if (req_succeeded and
                "ORIGIN" in req.headers and
                and req.method == 'OPTIONS'
                and req.get_header('Access-Control-Request-Method')
            ):
                # NOTE: This is a CORS preflight request. Patch the response accordingly.
    
                allow = resp.get_header('Allow')
                resp.delete_header('Allow')
    
                allow_headers = req.get_header(
                    'Access-Control-Request-Headers',
                    default='*'
                )
    
                resp.set_headers((
                    ('Access-Control-Allow-Methods', allow),
                    ('Access-Control-Allow-Headers', allow_headers),
                    ('Access-Control-Max-Age', '86400'),  # 24 hours
                ))
    

    完成后,您现在可以将其添加到中间件中,例如-

    api = falcon.API(middleware=[
        CORSMiddleware(),
    ])
    

    如果您不想使用上述方法,可以继续使用falcon-cors

    from falcon_cors import CORS
    
    cors = CORS(
        # allow_all_origins=False,
        allow_origins_list=whitelisted_origins,
        # allow_origins_regex=None,
        # allow_credentials_all_origins=True,
        # allow_credentials_origins_list=whitelisted_origins,
        # allow_credentials_origins_regex=None,
        allow_all_headers=True,
        # allow_headers_list=[],
        # allow_headers_regex=None,
        # expose_headers_list=[],
        # allow_all_methods=True,
        allow_methods_list=whitelisted_methods
    )
    
    api = falcon.API(middleware=[
        cors.middleware,
    ])
    

    仅供参考,falcon 2.0.0 支持的方法 -
    'CONNECT'、'DELETE'、'GET'、'HEAD'、'OPTIONS'、'PATCH'、'POST'、'PUT'、'TRACE'

    【讨论】:

      猜你喜欢
      • 2016-04-20
      • 1970-01-01
      • 2016-12-24
      • 2016-08-21
      • 2017-12-24
      • 1970-01-01
      • 2018-08-16
      • 1970-01-01
      相关资源
      最近更新 更多