You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Safari浏览器CORS问题:Access-Control-Allow-Origin不允许指定主机

Troubleshooting Safari-Specific CORS Error: [host] not allowed by Access-Control-Allow-Origin

Hey there, sorry to hear Safari's throwing this stubborn CORS error while other browsers work fine—let's dive into the Safari-specific quirks that are likely causing this and walk through fixes:

  • Double-check exact Origin matching
    Safari is far stricter about Access-Control-Allow-Origin matching than Chrome or Firefox. Even tiny differences like capitalization (e.g., https://YourApp.com vs https://yourapp.com), missing port numbers, or protocol mismatches (http vs https) will trigger the error. Use Safari's Web Inspector (enable it via Preferences → Advanced → Show Develop menu in menu bar) to view the exact Origin header sent in your request, then confirm your API's response returns that exact string in Access-Control-Allow-Origin (no wildcards if credentials are involved).

  • Avoid wildcards with credentials
    If your request includes cookies, HTTP auth, or uses withCredentials: true, Safari will reject a wildcard * in Access-Control-Allow-Origin. Make sure your API returns the specific request Origin here, and also includes Access-Control-Allow-Credentials: true in both OPTIONS and POST responses. Even if you don't think you're sending credentials, Safari might auto-include cookies from related domains, triggering this check.

  • Clear Safari's cached site data
    Safari often caches OPTIONS preflight responses aggressively, which can lead to outdated Access-Control-Allow-Origin values being used. Go to Preferences → Privacy → Manage Website Data, find your frontend and API domains, delete their data, then restart Safari and retest.

  • Check third-party cookie settings
    Safari's default privacy settings block many third-party cookies, which can interfere with cross-domain requests that rely on them. Temporarily switch to "Allow all cookies" in Preferences → Privacy → Cookie and Website Data to test if this fixes the issue. If it does, you'll need to adjust your authentication flow (e.g., use token-based auth instead of cookies) or guide users to add your domain to their allowed list.

  • Validate OPTIONS preflight response
    Safari requires OPTIONS requests to return a 200/204 status code and include all necessary headers like Access-Control-Allow-Methods (matching your POST method) and Access-Control-Allow-Headers (matching any custom headers in your request). If your API returns a redirect (3xx) or missing headers for OPTIONS, Safari will fail the request immediately.

  • Rule out extensions/proxy interference
    Privacy-focused extensions (like ad blockers) or proxies can modify request/response headers or block cross-domain requests in Safari. Test in Private Browsing mode (which disables extensions) or disable any proxies to see if the error goes away.

Since your Chrome request works as expected, comparing the exact request/response headers from Safari's Web Inspector to Chrome's will likely reveal the mismatch Safari's catching.

内容的提问来源于stack exchange,提问作者danwoodbury

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 06:45:06