You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx反向代理FastAPI的CORS问题:*可用但指定域名失效

问题分析与解决方案

核心原因

你遇到的问题大概率是Nginx和FastAPI同时配置CORS导致头部冲突,或者Nginx未正确处理OPTIONS预检请求,导致指定域名的CORS头部没有被正确返回。

1. 双重CORS配置冲突

FastAPI的CORSMiddleware已经会自动添加Access-Control-Allow-Origin等头部,同时Nginx也配置了add_header添加相同头部,会导致响应中出现重复的Access-Control-Allow-Origin字段,浏览器会直接判定CORS错误。而用*时,两个地方都返回*,浏览器不会报错,但指定域名时,重复的头部值(或不一致的配置)都会触发错误。

2. Nginx的add_header默认行为限制

Nginx的add_header指令默认只在2xx/3xx状态码的响应中添加头部,而浏览器发送的OPTIONS预检请求如果没有被专门处理,可能返回非2xx状态(比如404),此时CORS头部不会被添加,导致报错。


解决步骤

方案一:仅用FastAPI处理CORS(推荐)

保留FastAPI的CORSMiddleware配置,删除Nginx中所有CORS相关的add_header指令:

修改后的Nginx location配置:

location /neurotalk/ {
    proxy_pass http://127.0.0.1:8443;  # Proxying to Uvicorn
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;

    # Additional settings
    proxy_read_timeout 90;
    proxy_connect_timeout 90;
    proxy_redirect off;

    # Disable buffering for streaming responses
    proxy_buffering off;
    proxy_request_buffering off;
}

FastAPI的配置保持不变即可,CORSMiddleware会自动处理所有CORS请求,包括OPTIONS预检。

方案二:仅用Nginx处理CORS

如果需要在Nginx层面统一处理CORS,删除FastAPI中的CORSMiddleware配置,然后修改Nginx配置,确保正确处理OPTIONS请求:

修改后的Nginx location配置:

location /neurotalk/ {
    proxy_pass http://127.0.0.1:8443;  # Proxying to Uvicorn
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;

    # Handle OPTIONS preflight requests
    if ($request_method = OPTIONS) {
        add_header 'Access-Control-Allow-Origin' 'https://frontend.example.com';
        add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS';
        add_header 'Access-Control-Allow-Headers' 'Authorization, Content-Type';
        add_header 'Access-Control-Max-Age' 1728000;  # Cache preflight response for 20 days
        add_header 'Content-Type' 'text/plain; charset=utf-8';
        add_header 'Content-Length' 0;
        return 204;  # No content response for preflight
    }

    # Add CORS headers to non-OPTIONS requests
    add_header 'Access-Control-Allow-Origin' 'https://frontend.example.com';
    add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS';
    add_header 'Access-Control-Allow-Headers' 'Authorization, Content-Type';

    # Additional settings
    proxy_read_timeout 90;
    proxy_connect_timeout 90;
    proxy_redirect off;

    # Disable buffering for streaming responses
    proxy_buffering off;
    proxy_request_buffering off;
}

验证步骤

  1. 修改配置后,重启Nginx和FastAPI服务
  2. 打开浏览器开发者工具(F12),切换到网络标签,重新发起请求
  3. 查看请求的响应头,确认Access-Control-Allow-Origin只出现一次,且值为https://frontend.example.com
  4. 检查OPTIONS预检请求的响应状态码为204,且包含正确的CORS头部

内容的提问来源于stack exchange,提问作者Diyar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 04:47:04