测试应用时Chrome正常但IE报SCRIPT7002: XMLHttpRequest错误求助
Hey there, let's dig into that IE-specific XMLHttpRequest error you're facing—this is a pretty common issue with older IE versions, so let's walk through the most likely causes and fixes step by step:
1. 跨域请求(CORS)兼容性问题
IE handles cross-origin requests way differently than modern browsers like Chrome. Here's what to check:
- For IE10/11: Make sure your server sends proper CORS headers (like
Access-Control-Allow-Origin). Note that IE doesn't allow the wildcard*if your request includes credentials (cookies, for example)—you need to specify the exact origin instead. - For IE9 and earlier: The standard
XMLHttpRequestdoesn't support CORS at all. You'll need to useXDomainRequestinstead, which has a different API (noonreadystatechange, justonload/onerrorhandlers) and stricter limitations (no custom headers, only GET/POST methods).
2. Local file protocol (file://) restrictions
If you're opening your app directly from the filesystem (using file://), IE's default security settings block XHR requests to both local and remote resources. Fixes here:
- Deploy your app to a local web server (like IIS, Apache, or even a simple tool like
http-server) and access it viahttp://localhostinstead. - As a temporary test workaround: Go to Internet Options → Security → Local Intranet → Custom Level, find "Access data sources across domains" under the "Miscellaneous" section, and set it to "Enable". (Don't leave this on permanently—it's a security risk.)
3. Security zone conflicts
IE categorizes sites into security zones (Internet, Local Intranet, Trusted Sites). If your app's page and the target API are in different zones, IE might block the request:
- Add the API's domain to the same security zone as your app, or add it to the Trusted Sites list.
- Check if "Protected Mode" is enabled for the zone—if it is, cross-zone requests often get blocked. You can toggle this off temporarily for testing (again, not recommended for regular use).
4. Unsupported request headers or methods
IE's XHR has strict rules around certain request details:
- Custom headers (other than standard ones like
Authorization) might trigger a preflight OPTIONS request—make sure your server handles these correctly. - IE9 and earlier don't support HTTP methods like
PUTorDELETEfor cross-origin requests. If you're using these, switch to POST for IE, or add server-side support to handle the method override. - Avoid using
Content-Type: application/jsonin IE9 XHR requests—useapplication/x-www-form-urlencodedinstead, since IE9 has trouble parsing JSON payloads with the standard XHR object.
5. Third-party plugin or security software interference
Sometimes IE add-ons (like ad blockers, antivirus tools, or privacy extensions) can intercept and block XHR requests. Try:
- Closing all IE plugins and restarting the browser.
- Launching IE in "No Add-ons" mode (go to Start → All Programs → Accessories → System Tools → Internet Explorer (No Add-ons)) to test if the issue goes away.
内容的提问来源于stack exchange,提问作者Ramana

