You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Bullhorn REST API遇302重定向CORS拦截问题求助

Bullhorn REST API跨域重定向问题求助

我在自己的网站中使用Bullhorn REST API,对应的JavaScript代码如下:

var myHeaders = new Headers();
var requestOptions = {
  method: "GET",
  redirect: "follow",
  headers: myHeaders,
};
const url_part1 = "https://auth.bullhornstaffing.com/oauth/authorize?client_id=";
const url_part2 = "&response_type=code&username=";
const url_part3 = "&password=";
const url_part4 = "&action=Login";
const full_url =
  url_part1 +
  client_id +
  url_part2 +
  username +
  url_part3 +
  password +
  url_part4;
response = await fetch(full_url, requestOptions);

问题现象

  • 当client_id、用户名或密码错误时,接口返回200 OK,无任何跨域问题(即使没配置CORS,这点我不太理解)
  • 当凭证信息正确时,接口触发302临时重定向,同时出现CORS拦截错误:
Access to fetch at 'https://welcome.bullhornstaffing.com/?code=*************' (redirected from 'https://auth.bullhornstaffing.com/oauth/authorize?client_id=*******&response_type=code&username=*****&password=******&action=Login') from origin '*****' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. If an opaque response serves your needs, set the request's mode to 'no-cors' to fetch the resource with CORS disabled.

已尝试的解决方案

我试过网上多种方案,比如在.htaccess中添加跨域配置:

<IfModule mod_headers.c>
    Header set Access-Control-Allow-Origin "http://localhost:3000"
    Header set Access-Control-Allow-Credentials "true"
    Header set Access-Control-Allow-Methods "GET, POST, OPTIONS"
    Header set Access-Control-Allow-Headers "Origin, Content-Type, Accept"
</IfModule>

配置后,初始请求的响应头已包含以下跨域字段:

Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Accept, Authorization, Content-Type, Origin, highLevelCallStack, uniqueCallId, x-requested-with
Access-Control-Allow-Methods: POST, GET, PUT, OPTIONS, DELETE
Access-Control-Allow-Origin: *******
Access-Control-Max-Age: 86400

但问题依旧:重定向仍会触发,且重定向后的页面响应头中完全没有这些跨域字段,这应该就是报错的根源。我还试过修改functions.php等方法,翻了20多篇Stack Overflow帖子,都没解决问题。

补充信息

我在本地通过Chrome扩展发起请求时,只要在manifest.json中添加"host_permissions": ["https://*/", "http://*/"]就能正常工作,哪怕响应头里没有Access-Control-Allow-*相关字段。本地请求的Sec-Fetch-Site字段值为none,而网站发起的请求中该字段值是cross-site,我不清楚这个字段的作用,也不知道怎么修改。

求解决思路

请问该如何解决这个跨域重定向的问题?


内容的提问来源于stack exchange,提问作者FluidMechanics Potential Flows

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 05:07:44