You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Authenik获取token时出现CORS错误,寻求解决方案

问题:Authentik OAuth令牌请求遭遇CORS错误

环境背景

  • 已在Nginx Proxy Manager后方部署Authentik 2022.10.1实例,可通过域名auth.<mydomain.tld>访问
  • 实例对接本地LDAP服务获取用户凭证,已成功为另一服务器上的Portainer配置OAuth登录
  • 当前正在为自有MERN栈网站实现OAuth登录流程,已成功获取作为GET参数返回的授权code

问题描述

使用axios.post()携带code、client_id、client_secret等参数,请求https://auth.<mydomain.tld>/application/o/token/获取令牌时,浏览器返回400错误,提示:CORS策略阻止请求,目标资源缺少'Access-Control-Allow-Origin'头。

浏览器响应头详情

cache-control: no-store
content-encoding: gzip
content-length: 140
content-type: application/json
date: Wed, 16 Nov 2022 18:16:41 GMT
pragma: no-cache
referrer-policy: same-origin
server: openresty
vary: Accept-Encoding
vary: Cookie
x-authentik-id: c0d8606a80fa4d88a32e7b93dd202803
x-content-type-options: nosniff
x-frame-options: DENY
x-powered-by: authentik

已尝试的无效操作

  • 查阅Stack Overflow相关帖子并尝试方案,未解决问题
  • 在POST请求中手动添加CORS相关请求头,无效果
  • 开发时参考Google OAuth文档实现流程

代码逻辑说明

前端通过axios发送POST请求至Authentik令牌端点,携带授权code、客户端ID、客户端密钥等必要参数,请求格式遵循OAuth 2.0规范。


内容的提问来源于stack exchange,提问作者LinuxSquare

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 19:50:46