You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Flask服务器预检请求响应未通过跨域访问控制校验问题咨询

Fixing Flask CORS Preflight Request Failure

Hey there, let's work through this CORS preflight issue you're hitting with your Flask server. I've run into this exact problem a few times, so here are some practical fixes to get your cross-origin requests working:

1. Upgrade Your Flask-CORS Configuration

The basic CORS(app) setup often isn't enough for requests that trigger a preflight (like those with custom headers, PUT/DELETE methods, or non-standard content types). Try expanding your CORS initialization to explicitly allow the necessary methods, headers, and origins:

# Replace your current CORS(app) line with this
CORS(app, resources={
    r"/*": {
        "origins": "*",  # Allow all origins for development; restrict in production
        "methods": ["GET", "POST", "PUT", "DELETE", "OPTIONS"],
        "allow_headers": "*"
    }
})
  • origins="*" is great for local development, but in production, replace it with your frontend's actual domain (e.g., ["https://your-app.com"]) for security.
  • Explicitly listing OPTIONS ensures the preflight request is handled correctly, which is the root of your error.

2. Ensure OPTIONS Requests Are Handled

If the expanded CORS config still doesn't work, you can manually add a handler for OPTIONS requests to guarantee the right headers are sent. Add this route to your code:

@app.route('/', defaults={'path': ''}, methods=['OPTIONS'])
@app.route('/<path:path>', methods=['OPTIONS'])
def handle_options(path):
    response = make_response()
    response.headers["Access-Control-Allow-Origin"] = "*"
    response.headers["Access-Control-Allow-Methods"] = "GET, POST, PUT, DELETE, OPTIONS"
    response.headers["Access-Control-Allow-Headers"] = "*"
    return response

This catches all OPTIONS requests across your entire app and sets the required CORS headers directly.

3. Check for Conflicting Middleware or Decorators

Double-check if you have any custom before_request or after_request functions that might be overriding the CORS headers added by Flask-CORS. Make sure those functions don't overwrite headers like Access-Control-Allow-Origin unless you intend to.

Also, if you're using the @cross_origin() decorator on specific routes, ensure it's configured consistently with your global CORS setup (mixing both can sometimes cause conflicts).

Quick Test After Changes

Restart your Flask server, then try sending a preflight request (you can use tools like Postman or curl to simulate this). If the response includes the Access-Control-Allow-Origin, Access-Control-Allow-Methods, and Access-Control-Allow-Headers headers, your issue should be resolved.

内容的提问来源于stack exchange,提问作者flashburn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 08:05:15