You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure APIM策略中配置CORS错误的响应体

解决Azure APIM中CORS不匹配时返回自定义响应的问题

要实现Origin不在允许列表时返回自定义响应体的需求,你需要调整策略逻辑,不再依赖CORS策略的默认终止行为,而是手动判断Origin并返回自定义响应。具体配置如下:

<inbound>
    <!-- 手动判断Origin是否在允许列表,不匹配则返回自定义响应 -->
    <choose>
        <when condition="@(!context.Request.Headers.GetValueOrDefault("Origin", "").Equals("https://happygamer.com", StringComparison.OrdinalIgnoreCase))">
            <return-response>
                <set-status code="403" reason="Forbidden" />
                <set-header name="Content-Type" exists-action="override">
                    <value>application/json</value>
                </set-header>
                <set-body>{"msg":"COR issue"}</set-body>
            </return-response>
        </when>
    </choose>

    <!-- 调整后的CORS策略,关闭自动终止不匹配请求 -->
    <cors allow-credentials="false" terminate-unmatched-request="false">
        <allowed-origins>
            <origin>https://happygamer.com</origin>
        </allowed-origins>
        <allowed-methods>
            <method>*</method>
        </allowed-methods>
        <allowed-headers>
            <header>*</header>
        </allowed-headers>
        <expose-headers>
            <header>*</header>
        </expose-headers>
    </cors>
</inbound>

关键配置说明

  • choose策略:通过表达式判断请求的Origin头是否与允许的源匹配,不匹配时触发return-response。如果有多个允许的Origin,可以修改条件为:
    <when condition="@(!new[]{"https://happygamer.com", "https://another-domain.com"}.Contains(context.Request.Headers.GetValueOrDefault("Origin", ""), StringComparer.OrdinalIgnoreCase))">
    
  • return-response策略:自定义返回的状态码(推荐用403,更符合权限拒绝的语义)、响应头和响应体,完全替代默认的空200响应。
  • CORS策略调整:将terminate-unmatched-request设为false,因为不匹配的请求已经被前面的逻辑拦截处理,不需要CORS策略再自动终止。

内容的提问来源于stack exchange,提问作者lonelearner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 09:11:05