CrowCpp配置CORS仍遇跨域拦截问题求助
CrowCpp CORS预检请求404问题解决办法
问题描述
参照CrowCpp官方CORS示例配置中间件后,仍收到跨域错误:
Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at http://localhost:4567/sign-up. (Reason: CORS preflight response did not succeed). Status code: 404.
配置代码如下:app.cpp:
#include "app.hpp" #include <vector> #include "crow.h" #include <crow/middlewares/cors.h> #include <c1/authentication/authentication_controller.hpp> #include <c1/user/user_controller.hpp> namespace c1 { void App::run() { std::vector<Controller*> controllers{ new AuthenticationController(""), new UserController("user") }; crow::App<crow::CORSHandler> app; auto& cors = app.get_middleware<crow::CORSHandler>(); cors .global() .origin("http://localhost:3000") .methods("POST"_method, "GET"_method, "PUT"_method, "DELETE"_method) .allow_credentials(); for (const auto i : controllers) { app.register_blueprint(i->get()); i->setRoutes(); } app.port(4567).multithreaded().run(); } } // c
尝试在控制器手动设置响应头部后问题依旧:authentication_controller.cpp:
#include "authentication_controller.hpp" #include <iostream> #include <crow/app.h> namespace c1 { void AuthenticationController::setRoutes() { CROW_BP_ROUTE(get(), "/sign-up").methods(crow::HTTPMethod::Post)([](const crow::request& req, crow::response& res) { const auto json = crow::json::load(req.body); std::cout << json << std::endl; res.set_header("Access-Control-Allow-Origin", "*"); res.set_header("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE, OPTIONS"); res.set_header("Access-Control-Allow-Headers", "Content-Type, Authorization, X-Requested-With"); res.set_header("Access-Control-Allow-Credentials", "true"); }); } } // c
问题原因
- 预检请求(OPTIONS方法)未被纳入CORS允许的方法列表,导致中间件无法拦截处理。
- 蓝图注册与路由设置顺序颠倒:先注册蓝图再设置路由,导致路由未被正确添加到应用中,OPTIONS请求返回404。
- 手动设置的CORS头部与中间件配置冲突,且无法覆盖预检请求的处理逻辑。
解决办法
1. 修改app.cpp配置
- 在CORS全局配置中添加
OPTIONS方法支持 - 调整顺序:先设置路由,再注册蓝图
#include "app.hpp" #include <vector> #include "crow.h" #include <crow/middlewares/cors.h> #include <c1/authentication/authentication_controller.hpp> #include <c1/user/user_controller.hpp> namespace c1 { void App::run() { std::vector<Controller*> controllers{ new AuthenticationController(""), new UserController("user") }; crow::App<crow::CORSHandler> app; auto& cors = app.get_middleware<crow::CORSHandler>(); cors .global() .origin("http://localhost:3000") .methods("POST"_method, "GET"_method, "PUT"_method, "DELETE"_method, "OPTIONS"_method) // 添加OPTIONS方法 .allow_credentials(); for (const auto i : controllers) { i->setRoutes(); // 先设置路由 app.register_blueprint(i->get()); // 再注册蓝图 } app.port(4567).multithreaded().run(); } } // c
2. 简化authentication_controller.cpp
移除手动设置的CORS头部,由中间件统一处理:
#include "authentication_controller.hpp" #include <iostream> #include <crow/app.h> namespace c1 { void AuthenticationController::setRoutes() { CROW_BP_ROUTE(get(), "/sign-up").methods(crow::HTTPMethod::Post)([](const crow::request& req, crow::response& res) { const auto json = crow::json::load(req.body); std::cout << json << std::endl; // 仅处理业务逻辑,CORS头部由中间件自动添加 res.code = 200; res.body = "Sign up request processed"; }); } } // c
额外说明
- 开启
allow_credentials()后,不能用*作为Origin,必须指定具体源(如http://localhost:3000),这一点原有配置是正确的。 - 若需对特定路由单独配置CORS,可使用
cors.route("/path")进行精细化设置,无需全局覆盖。
内容的提问来源于stack exchange,提问作者milanHrabos
相关产品推荐
相关产品推荐

