Safari浏览器CORS问题:Access-Control-Allow-Origin不允许指定主机
[host] not allowed by Access-Control-Allow-Origin Hey there, sorry to hear Safari's throwing this stubborn CORS error while other browsers work fine—let's dive into the Safari-specific quirks that are likely causing this and walk through fixes:
Double-check exact Origin matching
Safari is far stricter aboutAccess-Control-Allow-Originmatching than Chrome or Firefox. Even tiny differences like capitalization (e.g.,https://YourApp.comvshttps://yourapp.com), missing port numbers, or protocol mismatches (http vs https) will trigger the error. Use Safari's Web Inspector (enable it via Preferences → Advanced → Show Develop menu in menu bar) to view the exactOriginheader sent in your request, then confirm your API's response returns that exact string inAccess-Control-Allow-Origin(no wildcards if credentials are involved).Avoid wildcards with credentials
If your request includes cookies, HTTP auth, or useswithCredentials: true, Safari will reject a wildcard*inAccess-Control-Allow-Origin. Make sure your API returns the specific request Origin here, and also includesAccess-Control-Allow-Credentials: truein both OPTIONS and POST responses. Even if you don't think you're sending credentials, Safari might auto-include cookies from related domains, triggering this check.Clear Safari's cached site data
Safari often caches OPTIONS preflight responses aggressively, which can lead to outdatedAccess-Control-Allow-Originvalues being used. Go to Preferences → Privacy → Manage Website Data, find your frontend and API domains, delete their data, then restart Safari and retest.Check third-party cookie settings
Safari's default privacy settings block many third-party cookies, which can interfere with cross-domain requests that rely on them. Temporarily switch to "Allow all cookies" in Preferences → Privacy → Cookie and Website Data to test if this fixes the issue. If it does, you'll need to adjust your authentication flow (e.g., use token-based auth instead of cookies) or guide users to add your domain to their allowed list.Validate OPTIONS preflight response
Safari requires OPTIONS requests to return a 200/204 status code and include all necessary headers likeAccess-Control-Allow-Methods(matching your POST method) andAccess-Control-Allow-Headers(matching any custom headers in your request). If your API returns a redirect (3xx) or missing headers for OPTIONS, Safari will fail the request immediately.Rule out extensions/proxy interference
Privacy-focused extensions (like ad blockers) or proxies can modify request/response headers or block cross-domain requests in Safari. Test in Private Browsing mode (which disables extensions) or disable any proxies to see if the error goes away.
Since your Chrome request works as expected, comparing the exact request/response headers from Safari's Web Inspector to Chrome's will likely reveal the mismatch Safari's catching.
内容的提问来源于stack exchange,提问作者danwoodbury

