You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CrowCpp配置CORS仍遇跨域拦截问题求助

CrowCpp CORS预检请求404问题解决办法

问题描述

参照CrowCpp官方CORS示例配置中间件后,仍收到跨域错误:

Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at http://localhost:4567/sign-up. (Reason: CORS preflight response did not succeed). Status code: 404.

配置代码如下:
app.cpp:

#include "app.hpp"
#include <vector>
#include "crow.h"
#include <crow/middlewares/cors.h>

#include <c1/authentication/authentication_controller.hpp>
#include <c1/user/user_controller.hpp>

namespace c1
{
void App::run()
{
    std::vector<Controller*> controllers{
        new AuthenticationController(""),
        new UserController("user")
    };

    crow::App<crow::CORSHandler> app;
    auto& cors = app.get_middleware<crow::CORSHandler>();
    cors
        .global()
        .origin("http://localhost:3000")
        .methods("POST"_method, "GET"_method, "PUT"_method, "DELETE"_method)
        .allow_credentials();

    for (const auto i : controllers)
    {
        app.register_blueprint(i->get());
        i->setRoutes();
    }

    app.port(4567).multithreaded().run();
}
} // c

尝试在控制器手动设置响应头部后问题依旧:
authentication_controller.cpp:

#include "authentication_controller.hpp"
#include <iostream>
#include <crow/app.h>

namespace c1
{
void AuthenticationController::setRoutes()
{
    CROW_BP_ROUTE(get(), "/sign-up").methods(crow::HTTPMethod::Post)([](const crow::request& req, crow::response& res)
    {
        const auto json = crow::json::load(req.body);
        std::cout << json << std::endl;
        res.set_header("Access-Control-Allow-Origin", "*");
        res.set_header("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE, OPTIONS");
        res.set_header("Access-Control-Allow-Headers", "Content-Type, Authorization, X-Requested-With");
        res.set_header("Access-Control-Allow-Credentials", "true");
    });
}
} // c

问题原因

  1. 预检请求(OPTIONS方法)未被纳入CORS允许的方法列表,导致中间件无法拦截处理。
  2. 蓝图注册与路由设置顺序颠倒:先注册蓝图再设置路由,导致路由未被正确添加到应用中,OPTIONS请求返回404。
  3. 手动设置的CORS头部与中间件配置冲突,且无法覆盖预检请求的处理逻辑。

解决办法

1. 修改app.cpp配置

  • 在CORS全局配置中添加OPTIONS方法支持
  • 调整顺序:先设置路由,再注册蓝图
#include "app.hpp"
#include <vector>
#include "crow.h"
#include <crow/middlewares/cors.h>

#include <c1/authentication/authentication_controller.hpp>
#include <c1/user/user_controller.hpp>

namespace c1
{
void App::run()
{
    std::vector<Controller*> controllers{
        new AuthenticationController(""),
        new UserController("user")
    };

    crow::App<crow::CORSHandler> app;
    auto& cors = app.get_middleware<crow::CORSHandler>();
    cors
        .global()
        .origin("http://localhost:3000")
        .methods("POST"_method, "GET"_method, "PUT"_method, "DELETE"_method, "OPTIONS"_method) // 添加OPTIONS方法
        .allow_credentials();

    for (const auto i : controllers)
    {
        i->setRoutes(); // 先设置路由
        app.register_blueprint(i->get()); // 再注册蓝图
    }

    app.port(4567).multithreaded().run();
}
} // c

2. 简化authentication_controller.cpp

移除手动设置的CORS头部,由中间件统一处理:

#include "authentication_controller.hpp"
#include <iostream>
#include <crow/app.h>

namespace c1
{
void AuthenticationController::setRoutes()
{
    CROW_BP_ROUTE(get(), "/sign-up").methods(crow::HTTPMethod::Post)([](const crow::request& req, crow::response& res)
    {
        const auto json = crow::json::load(req.body);
        std::cout << json << std::endl;
        
        // 仅处理业务逻辑,CORS头部由中间件自动添加
        res.code = 200;
        res.body = "Sign up request processed";
    });
}
} // c

额外说明

  • 开启allow_credentials()后,不能用*作为Origin,必须指定具体源(如http://localhost:3000),这一点原有配置是正确的。
  • 若需对特定路由单独配置CORS,可使用cors.route("/path")进行精细化设置,无需全局覆盖。

内容的提问来源于stack exchange,提问作者milanHrabos

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 17:52:42