You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Origin头为不同子域名时PUT请求返回403,CORS已配置通配符

跨域PUT请求403 Forbidden问题求助

我已排查该问题数日,近乎放弃。以下为测试情况:

正常请求

curl -X "PUT" "https://working.exampledomain.com/rest/myendpoint" -H "origin: https://working.exampledomain.com" -H "accept: application/json" -H "authorization: Bearer eyJddXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxOTg5MDMiLCJhaWQiOiIiLCJleHAiOjEuNzQzNDMyNDM1RTksImlhdCI6MS43MzgyNasdfzIjoiIn0.9lh5WqdFojv3uaDJA4lGwOqNARzyvniuXNB1id0R6KY" -H "content-type: application/json" -H "x-api-client-version: 2" -H "x-api-key: oL8oIPrFLBV5DZqNNNDNDfp6T9v5OEYh7FJuDHy" --data-raw "{\"assignment_status\":\"My Update\"}" -v

返回403的请求

curl -X "PUT" "https://working.exampledomain.com/rest/myendpoint" -H "origin: https://NOTworking.exampledomain.com" -H "accept: application/json" -H "authorization: Bearer eyJddXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxOTg5MDMiLCJhaWQiOiIiLCJleHAiOjEuNzQzNDMyNDM1RTksImlhdCI6MS43MzgadsfibGFfaWRzIjoiIn0.9lh5WqdFojv3uaDJA4lGwOqNARzyvniuXNB1id0R6KY" -H "content-type: application/json" -H "x-api-client-version: 2" -H "x-api-key: oL8oIPrFLBV5DZqNNNDNDfp6T9v5OEYh7FJuDHy" --data-raw "{\"assignment_status\":\"My Update\"}" -v

注:两个请求仅Origin域名不同。

失败请求返回结果

Server Error
403 - Forbidden: Access is denied.
You do not have permission to view this directory or page using the credentials that you supplied.

已做排查动作

  • 无法在日志或其他位置找到更多错误信息
  • web.config中已启用CORS,禁用后问题依旧,配置如下:
    <cors enabled="true" failUnlistedOrigins="true">
        <add origin="*" allowed="false" />
        <add origin="https://*.exampledomain.com" allowCredentials="true">
            <allowHeaders allowAllRequestedHeaders="true" />
            <allowMethods>
                <add method="HEAD" />
                <add method="GET" />
                <add method="PUT" />
                <add method="POST" />
                <add method="DELETE" />
                <add method="OPTIONS" />
            </allowMethods>             
         </add>
    </cors>
    
  • 通过hosts文件将域名指向本地,排除外部网络问题
  • 已禁用Basic auth,启用匿名访问
  • 为403错误启用了Failed Request Logging,但未生成日志
  • 请求由Coldfusion处理,已确保IIS用户、应用池用户等对isapi dll(jakarta/isapi_redirect.dll)的权限配置正确

注:这似乎并非CORS问题,因为NOTworking域名和PUT方法均已被允许。失败时的完整响应及失败请求日志中的警告有相关截图记录。

恳请提供技术指导。


内容的提问来源于stack exchange,提问作者user2666528

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 12:47:16