You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Microsoft Edge中XMLHttpRequest跨域请求失败(CORS头缺失)如何解决?

Fixing the Cross-Origin Request Blocked Error for Your SharePoint XML Request

Hey MarkusS, that CORS error you're hitting is super common when trying to pull resources across different domains—let's walk through your options to get that XML file loading properly in Edge.


1. Configure CORS on the SharePoint Server (Production-Grade Fix)

The root issue here is that the SharePoint server isn't sending the Access-Control-Allow-Origin header in its response. If you have access to the SharePoint admin panel or can coordinate with your IT team, this is the most sustainable solution for long-term use.

  • How to set it up:

    1. Navigate to your SharePoint site collection's admin settings.
    2. Look for CORS configuration options (usually under "Site Settings" > "Site Collection Administration" depending on your SharePoint version).
    3. Add your frontend application's domain as an allowed origin (e.g., https://your-app-domain.com). For testing, you can use * to allow all origins, but avoid this in production for security reasons.
    4. Make sure the allowed HTTP methods include GET (since that's what your code uses).
  • PowerShell alternative (if you have server access):

    # Connect to your SharePoint site
    $site = Get-SPSite "https://spp-0006.int.kaufland/sites/topic-0193"
    $web = $site.OpenWeb()
    
    # Set the CORS header to allow your frontend domain
    $web.AdditionalHeaders["Access-Control-Allow-Origin"] = "https://your-frontend-domain.com"
    $web.Update()
    

2. Use a Proxy Server (If You Can't Modify SharePoint Settings)

If you don't have control over the SharePoint server's CORS rules, a proxy server acts as a middleman to bypass the cross-origin restriction. Your frontend requests the proxy, which then fetches the XML from SharePoint and sends it back to you—since the proxy and your frontend are "same-origin," the browser won't block the request.

  • Example Node.js proxy:
    First, install dependencies:
    npm install express request
    
    Then create a proxy.js file:
    const express = require('express');
    const request = require('request');
    const app = express();
    
    // Endpoint to proxy the XML request
    app.get('/fetch-xml', (req, res) => {
      const sharePointUrl = 'https://spp-0006.int.kaufland/sites/topic-0193/Shared%20Documents/Dateien/XML_Marktliste.xml';
      req.pipe(request(sharePointUrl)).pipe(res);
    });
    
    app.listen(3000, () => console.log('Proxy running on http://localhost:3000'));
    
    Update your frontend code to call the proxy instead of the direct SharePoint URL:
    var xhr = new XMLHttpRequest();
    xhr.open('GET', 'http://localhost:3000/fetch-xml', false);
    xhr.send();
    

3. Use SharePoint's REST API (SharePoint-Specific Approach)

Since you're accessing a SharePoint file, leveraging the SharePoint REST API is a more integrated solution. This method handles authentication and CORS properly if your app has the right permissions set up.

  • Updated code example:
    var xhr = new XMLHttpRequest();
    // Use SharePoint's REST API endpoint to get the file content
    const restUrl = 'https://spp-0006.int.kaufland/sites/topic-0193/_api/web/GetFileByServerRelativeUrl(\'/sites/topic-0193/Shared Documents/Dateien/XML_Marktliste.xml\')/$value';
    
    xhr.open('GET', restUrl, false);
    xhr.setRequestHeader('Accept', 'application/xml');
    // If your site requires authentication, add an Authorization header (e.g., Bearer token) here
    xhr.send();
    
    Note: You may need to register your app in SharePoint to get valid authentication tokens for this to work seamlessly.

4. Disable CORS in Edge (Only for Local Testing!)

If you're just debugging locally and need a quick, temporary fix (never use this in production), you can disable Edge's web security:

  • Right-click your Edge shortcut → Properties.
  • In the "Target" field, add this to the end (make sure there's a space before the first dash):
    --disable-web-security --user-data-dir="C:/EdgeDevSession"
    
  • Launch Edge using this shortcut—your cross-origin request will work, but your browser will be less secure, so close it when you're done testing.

内容的提问来源于stack exchange,提问作者MarkusS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 08:34:17