You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

POST请求触发No-Access-Control-Allow-Origin错误,GET请求正常求帮助

解决POST请求的CORS与404问题

Hey Kyle, let's work through this issue together—your GET request works but POST is failing with CORS + 404 errors, so we'll break this down step by step.

First, let's note the critical detail in your error: the preflight OPTIONS request returned a 404 status code. That's likely the root cause of the CORS error—if the server can't even find the endpoint to handle the OPTIONS check, it can't send back the required Access-Control-Allow-Origin header.

Step 1: Fix the 404 for the OPTIONS/POST endpoint

Your GET request to /v1/call-rates/base works, but the POST to /v1/call-rates/base/search doesn't. Let's verify:

  • Do you have an actionSearch() method in your controller that handles /call-rates/base?
  • Does your route configuration map the POST request to this action? In Yii2's urlManager, make sure there's a rule like:
    'v1/call-rates/base/search' => 'call-rates/base/search',
    
  • Most importantly: does your action allow OPTIONS and POST methods? By default, Yii2 actions only accept GET. Add a VerbFilter to your controller's behaviors to explicitly allow these methods for the search action:
    public function behaviors() {
        $behaviors = parent::behaviors();
        
        // Add verb filter first
        $behaviors['verbs'] = [
            'class' => \yii\filters\VerbFilter::className(),
            'actions' => [
                'search' => ['POST', 'OPTIONS'], // Allow POST and preflight OPTIONS
            ],
        ];
    
        // Your existing CORS and auth config goes here...
        return $behaviors;
    }
    

Step 2: Ensure CORS Filter runs before Authentication

In Yii2, behavior execution order matters. Your current code adds corsFilter before re-adding authenticator, which is good—but let's make it explicit to avoid any edge cases. Add an order property to your CORS filter to guarantee it runs first:

$behaviors['corsFilter'] = [
    'class' => Cors::className(),
    'order' => \yii\filters\Cors::ORDER_FIRST, // Force CORS to run before auth
    'cors' => [
        'Origin' => ['*'],
        'Access-Control-Allow-Methods' => ['POST', 'PUT', 'OPTIONS', 'PATCH', 'GET', 'HEAD'],
        // Simplify allowed headers—no need to include CORS-specific headers here
        'Access-Control-Request-Headers' => ['Authorization', 'Content-Type', 'Origin'],
        'Access-Control-Expose-Headers' => ['X-Pagination-Page-Count','X-Pagination-Total-Count', 'Origin'],
    ],
];

This ensures the preflight OPTIONS request (which doesn't include an auth token) isn't blocked by the HttpBearerAuth filter before the CORS check can happen.

Step 3: Test the Preflight Request

Use curl to manually send an OPTIONS request and verify the CORS headers are present:

curl -X OPTIONS http://api.dev/v1/call-rates/base/search \
  -H "Origin: http://localhost:63342" \
  -H "Access-Control-Request-Method: POST" \
  -H "Access-Control-Request-Headers: Content-Type" \
  -v

You should see a 200 status code, and the response should include:

  • Access-Control-Allow-Origin: *
  • Access-Control-Allow-Methods: POST, PUT, OPTIONS, PATCH, GET, HEAD
  • Access-Control-Allow-Headers: Authorization, Content-Type, Origin

If you get these headers, the CORS config is working—now you just need to make sure your POST request to /search returns valid data (not 404).

Step 4: Double-Check Your POST Request

Make sure your POST request is targeting the exact correct endpoint, and that the request body matches what your actionSearch() expects. If the endpoint exists and accepts POST, the CORS error should disappear once the preflight check passes.


内容的提问来源于stack exchange,提问作者Kyle

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:57:21