You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core 7 MVC跳转外部网站遇CORS错误,求排查方案

ASP.NET Core 7 MVC跳转外部网站时出现CORS错误的排查与解决

问题场景

我正在使用ASP.NET Core 7 MVC框架,希望在某个结果为true时跳转到外部网站。控制器中编写了如下代码:

public ActionResult CalculateSomething(string encIds, string url)
{
    try
    {    
        resultIs = true;

        if (resultIs)
        {
            string newUrl = "https://www.ad.nl";

            return Redirect(newUrl);
        }
    }
    catch (Exception ex)
    {
        string s = ex.Message;
        return Json(s);
    }
}

在appsettings中配置了:

"AllowedCorsOrigins": "https://localhost:7065/",

program.cs中的CORS配置如下:

var allowedCorsOrigins = configuration.GetValue<string>("AllowedCorsOrigins");
    
builder.Services.AddCors(options =>
{
    options.AddPolicy("AllowSpecificOrigin",
        builder =>
        {
            builder.WithOrigins(allowedCorsOrigins)
                    .AllowAnyHeader()
                    .AllowAnyMethod();
        });
});

app.UseCors("AllowSpecificOrigin");

操作时出现了CORS错误,请问哪里配置或代码有误?

问题原因

  1. CORS源地址匹配问题:AllowedCorsOrigins配置末尾带斜杠/,而WithOrigins要求源地址不能带末尾斜杠,会导致匹配失败。
  2. AJAX场景下的跳转逻辑错误:如果是前端通过AJAX调用该接口,Redirect返回的302状态码不会直接触发浏览器页面跳转,浏览器会尝试自动跟进跳转请求,此时目标网站https://www.ad.nl不在CORS允许列表中,就会触发跨域错误。同时接口混合返回RedirectResult和JsonResult,也会导致前端处理逻辑混乱。
  3. 中间件顺序问题:如果app.UseCors的位置不正确(比如放在app.UseRouting之前或app.UseAuthorization之后),CORS策略不会生效。

解决办法

1. 修正CORS源地址配置

修改appsettings.json,去掉源地址末尾的斜杠:

"AllowedCorsOrigins": "https://localhost:7065"

2. 调整接口逻辑适配AJAX场景

如果是前端AJAX调用接口,不要直接返回Redirect,而是返回包含目标URL的JSON数据,让前端主动处理跳转:

public ActionResult CalculateSomething(string encIds, string url)
{
    try
    {    
        bool resultIs = true;

        if (resultIs)
        {
            string newUrl = "https://www.ad.nl";
            return Json(new { success = true, redirectUrl = newUrl });
        }
        return Json(new { success = false });
    }
    catch (Exception ex)
    {
        return Json(new { success = false, error = ex.Message });
    }
}

前端接收响应后执行跳转:

fetch('/YourController/CalculateSomething?encIds=xxx&url=xxx')
  .then(res => res.json())
  .then(data => {
    if (data.success && data.redirectUrl) {
      window.location.href = data.redirectUrl;
    } else {
      console.error(data.error || '操作失败');
    }
  });

3. 确认中间件顺序

确保app.UseCors放在正确的位置,必须在app.UseRouting之后、app.UseAuthorization之前:

app.UseRouting();

app.UseCors("AllowSpecificOrigin");

app.UseAuthorization();

app.MapControllerRoute(
    name: "default",
    pattern: "{controller=Home}/{action=Index}/{id?}");

4. 非AJAX场景的验证

如果是用户直接访问该控制器方法的URL,CORS错误不应出现,此时可以清空浏览器缓存重试,或者检查是否有其他浏览器插件干扰跨域请求。

内容的提问来源于stack exchange,提问作者user1531040

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 08:05:06