解决Nginx POST请求中Access-Control-Allow-Origin头丢失问题
Nginx POST请求中Access-Control-Allow-Origin头丢失的解决办法
你的问题出在Nginx add_header 指令的默认行为上:该指令仅在响应状态码为2xx或3xx时才会添加头信息。OPTIONS请求直接返回204(属于2xx),所以跨域头能正常返回;但POST请求走proxy_pass后,若后端返回4xx、5xx这类非成功状态码,默认配置下add_header不会生效,导致跨域头丢失。
给你两种修改方案,按需选择:
方案一:强制所有状态码添加跨域头
在POST对应的add_header指令末尾加上always参数,让Nginx不管后端返回什么状态码,都把跨域头加到响应里:
location /api { proxy_pass http://127.0.0.1:3567/; if ($request_method = OPTIONS) { add_header "Access-Control-Allow-Origin" "http://localhost:8080"; add_header "Access-Control-Allow-Methods" "GET, POST, OPTIONS"; add_header "Content-Type" "text/plain"; add_header "Access-Control-Allow-Credentials" "true"; add_header "Access-Control-Allow-Headers" "content-type,rid,fdi-version"; add_header "Content-Length" 0; return 204; } # 关键:添加always参数 add_header "Access-Control-Allow-Origin" "http://localhost:8080" always; # 建议同步添加允许凭证的头,保持跨域配置一致 add_header "Access-Control-Allow-Credentials" "true" always; }
方案二:避免后端跨域头冲突(可选)
如果你的后端服务自身也返回Access-Control-Allow-Origin头,可能会和Nginx配置的头重复,导致浏览器报错。这时候可以先隐藏后端返回的跨域头,再用Nginx统一添加:
location /api { proxy_pass http://127.0.0.1:3567/; # 隐藏后端返回的跨域相关头,避免冲突 proxy_hide_header Access-Control-Allow-Origin; proxy_hide_header Access-Control-Allow-Credentials; if ($request_method = OPTIONS) { add_header "Access-Control-Allow-Origin" "http://localhost:8080"; add_header "Access-Control-Allow-Methods" "GET, POST, OPTIONS"; add_header "Content-Type" "text/plain"; add_header "Access-Control-Allow-Credentials" "true"; add_header "Access-Control-Allow-Headers" "content-type,rid,fdi-version"; add_header "Content-Length" 0; return 204; } add_header "Access-Control-Allow-Origin" "http://localhost:8080" always; add_header "Access-Control-Allow-Credentials" "true" always; }
内容的提问来源于stack exchange,提问作者nm980
相关产品推荐
相关产品推荐

