ArcGIS Enterprise访问Google Cloud Storage视频的CORS策略问题
问题背景
在ArcGIS Enterprise(https://gis.pomerleau.ca)中访问Google Cloud Storage存储的视频时,触发CORS策略拦截,错误信息:
Access to image at 'https://storage.googleapis.com/pomerleauoic/DJI_20240612163254_0001.MP4' from origin 'https://gis.pomerleau.ca' has been blocked by CORS policy: The value of the 'Access-Control-Allow-Credentials' header in the response is '' which must be 'true' when the request's credentials mode is 'include'
已执行以下操作但无效:
- 配置GCS存储桶CORS规则(允许
https://gis.pomerleau.ca的GET请求,指定响应头) - 用
gsutil cors get gs://pomerleauoic验证配置生效 - 清除浏览器缓存并在多浏览器/隐身模式测试
异常点:同一存储桶内部分公开视频可正常访问(如https://storage.googleapis.com/pomerleau/INSPECTION_C-EST_D-NORD_4min55.mp4),部分视频(如https://storage.googleapis.com/pomerleau/DJI_20240612165948_0001.MP4)触发错误。
解决建议
1. 补全CORS配置的allowCredentials字段
当前的CORS规则未显式声明允许凭证,GCS不会自动返回Access-Control-Allow-Credentials: true响应头。更新后的完整CORS配置JSON文件(例如cors-config.json):
[ { "origin": ["https://gis.pomerleau.ca"], "method": ["GET"], "responseHeader": ["Content-Type", "Access-Control-Allow-Origin", "Access-Control-Allow-Credentials"], "maxAgeSeconds": 3600, "allowCredentials": true } ]
执行命令重新应用配置:
gsutil cors set cors-config.json gs://pomerleauoic
再次用gsutil cors get gs://pomerleauoic确认allowCredentials字段已存在。
2. 检查问题视频的自定义元数据
同一桶内视频表现差异,可能是问题视频的自定义元数据覆盖了桶级CORS设置。执行命令查看视频元数据:
gsutil ls -L gs://pomerleau/DJI_20240612165948_0001.MP4
如果存在x-goog-meta-access-control-allow-credentials等自定义响应头,删除该元数据:
gsutil rm -h "x-goog-meta-access-control-allow-credentials" gs://pomerleau/DJI_20240612165948_0001.MP4
3. 绕过GCS边缘缓存验证
GCDN边缘节点可能缓存了旧的CORS响应头,添加查询参数强制绕过缓存测试:https://storage.googleapis.com/pomerleau/DJI_20240612165948_0001.MP4?nocache=1
若测试有效,等待缓存自然过期(通常1-24小时),或通过GCP控制台提交缓存刷新请求。
4. 对比请求头差异
用浏览器开发者工具Network面板,对比正常视频与问题视频的请求:
- 确认两者的
credentials模式均为include - 检查请求是否携带Cookie/Authorization头,这类头会触发凭证模式,需确保GCS配置允许
内容的提问来源于stack exchange,提问作者Noah Khounsombath

