求助:登录Saleor Dashboard时遭遇CORS错误(CORS被拦截)
Hey there! Let’s sort out that CORS error you’re facing when trying to log into your Saleor Dashboard. Since all three core services are up and running but cross-origin requests are getting blocked, this is almost always a configuration issue in your Saleor Core (Django) backend—let’s walk through the steps to fix it.
Step 1: Install & Configure Django CORS Headers
Saleor Core uses Django, so we’ll rely on the django-cors-headers package to handle cross-origin requests properly.
First, install the package if you haven’t already:
pip install django-cors-headers
Next, open your Saleor Core project’s settings.py file and make these changes:
- Add
corsheadersto yourINSTALLED_APPS:
INSTALLED_APPS = [ # ... other existing apps 'corsheaders', ]
- Add the CORS middleware to
MIDDLEWARE—make sure it comes beforedjango.middleware.common.CommonMiddleware:
MIDDLEWARE = [ 'corsheaders.middleware.CorsMiddleware', # Add this line first 'django.middleware.common.CommonMiddleware', # ... other existing middleware ]
- Whitelist your Saleor Dashboard’s URL in
CORS_ALLOWED_ORIGINS. For example, if your Dashboard is running onhttp://localhost:9000:
CORS_ALLOWED_ORIGINS = [ "http://localhost:9000", # Add any other origins you need (like your Storefront URL if needed) ]
- Enable credentials support (required for login sessions, which use cookies/auth tokens):
CORS_ALLOW_CREDENTIALS = True
Step 2: Verify Saleor Dashboard Environment Variables
Double-check that your Saleor Dashboard’s .env file is pointing to the correct Saleor Core API URL. It should look something like this:
NEXT_PUBLIC_API_URL=http://localhost:8000/graphql/
Make sure the URL matches where your Saleor Core is running (default is port 8000).
Step 3: Restart Services
After making these configuration changes, restart your Saleor Core server to apply the updates. Then try logging into the Dashboard again—this should resolve the CORS block.
Quick Note for Development Only
If you’re in a local dev environment and want to skip strict origin checking temporarily (never do this in production), you can add:
CORS_ALLOW_ALL_ORIGINS = True
But remember to replace this with specific origins once you’re ready for staging/production.
内容的提问来源于stack exchange,提问作者Alka Singla

