配置预检通道:POST请求外部API遇CORS头缺失问题求助
Let's break down your issue step by step—you've already put in work testing configs, so let's get this fixed.
First: Fix the Critical Typo in Your web.config
You're so close here! The header name you used is singular (Access-Control-Allow-Header) but it needs to be plural (Access-Control-Allow-Headers). Browsers are strict about this naming, so that's almost certainly the main reason your initial fix didn't work.
Here's the corrected web.config:
<?xml version="1.0" encoding="UTF-8"?> <configuration> <system.webServer> <httpProtocol> <customHeaders> <add name="Access-Control-Allow-Origin" value="*" /> <add name="Access-Control-Allow-Headers" value="Content-Type" /> <add name="Access-Control-Allow-Methods" value="POST, OPTIONS" /> </customHeaders> </httpProtocol> </system.webServer> </configuration>
I added Access-Control-Allow-Methods too, since preflight checks validate allowed request methods alongside headers—this covers the OPTIONS request your browser sends automatically.
Second: Ignore crossdomain.xml (It’s Not for Modern CORS)
Crossdomain.xml is a legacy file built for old technologies like Flash and Silverlight. Modern browsers don’t use it for standard CORS requests, so modifying it won’t help your issue. You can revert that file to its original state if you want—no harm done, but it’s irrelevant here.
Third: Add CORS Handling Directly in ColdFusion (Fallback/Backup)
Since you’re using ColdFusion as a bridge between JS and MySQL, adding CORS headers directly to your CFML script can act as a reliable fallback (or even the primary fix if IIS configs aren’t applying correctly). Here’s how:
- At the very top of your API endpoint’s CFM file, add these headers:
<cfheader name="Access-Control-Allow-Origin" value="*"> <cfheader name="Access-Control-Allow-Headers" value="Content-Type"> <cfheader name="Access-Control-Allow-Methods" value="POST, OPTIONS">
- Preflight requests use the
OPTIONSmethod, so you need to respond to those explicitly (otherwise ColdFusion might return a 404 or default error):
<cfif CGI.REQUEST_METHOD EQ "OPTIONS"> <!--- Respond to preflight with 200 OK and exit immediately ---> <cfheader statuscode="200" statustext="OK"> <cfexit> </cfif>
Fourth: Restart IIS to Apply web.config Changes
After editing web.config, you need to restart IIS for the new rules to take effect. On your EC2 instance, open Command Prompt as an administrator and run:
iisreset
This ensures IIS reloads the updated header configuration.
Quick Note on EC2 & AWS
You’re right—EC2 itself is just a virtual server, so CORS configs live in your server software (IIS) or application layer (ColdFusion). If you had a CloudFront distribution or Application Load Balancer in front of EC2, you could set CORS there, but since you’re working directly with the instance, focusing on IIS and ColdFusion is the correct approach.
Testing the Fix
After making these changes, send your POST request again. The preflight check should now recognize Content-Type in the Access-Control-Allow-Headers response, and your request should go through successfully.
内容的提问来源于stack exchange,提问作者Robbie Milejczak

