|
|
|
|
<!doctype html>
|
|
|
|
|
<html lang="en" dir="ltr" class="docs-wrapper plugin-docs plugin-id-default docs-version-current docs-doc-page docs-doc-id-cors" data-has-hydrated="false">
|
|
|
|
|
<head>
|
|
|
|
|
<meta charset="UTF-8">
|
|
|
|
|
<meta name="generator" content="Docusaurus v3.0.0">
|
|
|
|
|
<title data-rh="true">16. CORS 跨域 | Furion</title><meta data-rh="true" name="viewport" content="width=device-width,initial-scale=1"><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" property="og:url" content="http://furion.baiqian.ltd/docs/cors"><meta data-rh="true" property="og:locale" content="en"><meta data-rh="true" name="docusaurus_locale" content="en"><meta data-rh="true" name="docsearch:language" content="en"><meta data-rh="true" name="docusaurus_version" content="current"><meta data-rh="true" name="docusaurus_tag" content="docs-default-current"><meta data-rh="true" name="docsearch:version" content="current"><meta data-rh="true" name="docsearch:docusaurus_tag" content="docs-default-current"><meta data-rh="true" property="og:title" content="16. CORS 跨域 | Furion"><meta data-rh="true" name="description" content="16.1 什么是跨域"><meta data-rh="true" property="og:description" content="16.1 什么是跨域"><link data-rh="true" rel="icon" href="/img/favicon.ico"><link data-rh="true" rel="canonical" href="http://furion.baiqian.ltd/docs/cors"><link data-rh="true" rel="alternate" href="http://furion.baiqian.ltd/docs/cors" hreflang="en"><link data-rh="true" rel="alternate" href="http://furion.baiqian.ltd/docs/cors" hreflang="x-default"><link rel="alternate" type="application/rss+xml" href="/blog/rss.xml" title="Furion RSS Feed">
|
|
|
|
|
<link rel="alternate" type="application/atom+xml" href="/blog/atom.xml" title="Furion Atom Feed"><link rel="stylesheet" href="/assets/css/styles.3f87a095.css">
|
|
|
|
|
<script src="/assets/js/runtime~main.89709a83.js" defer="defer"></script>
|
|
|
|
|
<script src="/assets/js/main.10e5dc01.js" defer="defer"></script>
|
|
|
|
|
</head>
|
|
|
|
|
<body class="navigation-with-keyboard">
|
|
|
|
|
<script>!function(){function t(t){document.documentElement.setAttribute("data-theme",t)}var e=function(){try{return new URLSearchParams(window.location.search).get("docusaurus-theme")}catch(t){}}()||function(){try{return localStorage.getItem("theme")}catch(t){}}();t(null!==e?e:"light")}(),function(){try{const a=new URLSearchParams(window.location.search).entries();for(var[t,e]of a)if(t.startsWith("docusaurus-data-")){var n=t.replace("docusaurus-data-","data-");document.documentElement.setAttribute(n,e)}}catch(t){}}(),document.documentElement.setAttribute("data-announcement-bar-initially-dismissed",function(){try{return"true"===localStorage.getItem("docusaurus.announcement.dismiss")}catch(t){}return!1}())</script><div id="__docusaurus"><div class="floatbar_hUWl"><div class="qrcode_sWwE"><img title="微信扫码关注 Furion 官方公众号" src="/img/weixin_qrcode.jpg" style="display:block"><div>❤️ 关注 Furion 微信公众号有惊喜哦!</div></div><div style="display:flex;flex-direction:row-reverse;align-items:flex-start"><div class="title_SD0k">🫠 遇到问题了</div><div class="extend__5i1"><a class="item_Y35a" href="/docs/subscribe"><div style="flex:1"><div class="itemTitle_If_T">⭐️ VIP 服务 ⭐️</div><div class="itemDesc_dp7r">仅需 499 元/年,尊享 365 天项目无忧</div></div><div class="jiantou_mV_o"></div></a><div class="item_Y35a"><div style="flex:1"><div class="itemTitle_If_T">问题反馈</div><div class="itemDesc_dp7r">到 Furion 开源仓库反馈</div></div><div class="jiantou_mV_o"></div></div></div></div></div><div role="region" aria-label="Skip to main content"><a class="skipToContent_fXgn" href="#__docusaurus_skipToContent_fallback">Skip to main content</a></div><div class="announcementBar_mb4j" style="background-color:#4623d9;color:yellow" role="banner"><div class="content_knG7 announcementBarContent_xLdY">⭐️ 开通 VIP 服务仅需 499 元/年,尊享 365 天项目无忧 <a href="/docs/subscribe" style="background-color:rgb(199, 29, 36);color:#ffffff;padding:1px 10px;border-radius:3px;text-decoration:none;display:inline-block;margin:0 5px;font-size:12px;cursor:pointer;">立即开通</a>⭐️</div></div><nav aria-label="Main" class="navbar navbar--fixed-top navbarHideable_m1mJ"><div class="navbar__inner"><div class="navbar__items"><button aria-label="Toggle navigation bar" aria-expanded="false" class="navbar__toggle clean-btn" type="button"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/"><div class="navbar__logo"><img src="/img/furionlogo.png" alt="Furion Logo" class="themedComponent_mlkZ themedComponent--light_NVdE"><img src="/img/furionlogo.png" alt="Furion Logo" class="themedComponent_mlkZ themedComponent--dark_xIcU"></div><b class="navbar__title text--truncate">Furion</b></a><a aria-current="page" class="navbar__item navbar__link navbar__link--active" href="/docs/category/appendix">文档</a><a class="navbar__item navbar__link" href="/docs/global/app">静态类</a><a class="navbar__item navbar__link" href="/docs/settings/appsettings">配置</a><a class="navbar__item navbar__link" href="/blog">博客</a><div class="navbar__item dropdown dropdown--hoverable"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">更新日志</a><ul class="dropdown__menu"><li><a class="dropdown__link" href="/docs/upgrade">📝 查看日志(v4.9.1.7)</a></li><li><a class="dropdown__link" href="/docs/target">🚀 路线图</a></li></ul></div><a href="http://furion.baiqian.ltd/api/api" target="_blank" rel="noopener noreferrer" class="navbar__item navbar__link">API<svg width="13.5" height="13.5" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></div><div class="navbar__items navbar__it
|
|
|
|
|
<p>简单来说,当一个请求 <code>url</code> 的协议、域名、端口三者之间任意一个与当前页面 <code>url</code> 不同即为跨域。那为什么会出现跨域问题呢?</p>
|
|
|
|
|
<p>出于浏览器的同源策略限制。同源策略(Sameoriginpolicy)是一种约定,它是浏览器最核心也最基本的安全功能,如果缺少了同源策略,则浏览器的正常功能可能都会受到影响。可以说 <code>Web</code> 是构建在同源策略基础之上的,浏览器只是针对同源策略的一种实现。同源策略会阻止一个域的 javascript 脚本和另外一个域的内容进行交互。所谓同源(即指在同一个域)就是两个页面具有相同的协议(protocol),主机(host)和端口号(port)。</p>
|
|
|
|
|
<h2 class="anchor anchorWithHideOnScrollNavbar_WYt5" id="162-有跨域行为示例">16.2 有跨域行为示例<a href="#162-有跨域行为示例" class="hash-link" aria-label="Direct link to 16.2 有跨域行为示例" title="Direct link to 16.2 有跨域行为示例"></a></h2>
|
|
|
|
|
<table><thead><tr><th>当前页面 url</th><th>被请求页面 url</th><th>是否跨域</th><th>原因</th></tr></thead><tbody><tr><td><a href="http://www.baiqian.ltd/" target="_blank" rel="noopener noreferrer">http://www.baiqian.ltd/</a></td><td><a href="http://www.baiqian.ltd/index.html" target="_blank" rel="noopener noreferrer">http://www.baiqian.ltd/index.html</a></td><td>否</td><td>同源(协议、域名、端口号相同)</td></tr><tr><td><a href="http://www.baiqian.ltd/" target="_blank" rel="noopener noreferrer">http://www.baiqian.ltd/</a></td><td><a href="https://www.baiqian.ltd/index.html" target="_blank" rel="noopener noreferrer">https://www.baiqian.ltd/index.html</a></td><td>跨域</td><td>协议不同(http/https)</td></tr><tr><td><a href="http://www.baiqian.ltd/" target="_blank" rel="noopener noreferrer">http://www.baiqian.ltd/</a></td><td><a href="http://www.baidu.com/" target="_blank" rel="noopener noreferrer">http://www.baidu.com/</a></td><td>跨域</td><td>主域名不同(baiqian.ltd/baidu.com)</td></tr><tr><td><a href="http://furion.baiqian.ltd/" target="_blank" rel="noopener noreferrer">http://furion.baiqian.ltd/</a></td><td><a href="http://fur.baiqian.ltd/" target="_blank" rel="noopener noreferrer">http://fur.baiqian.ltd/</a></td><td>跨域</td><td>子域名不同(furion/fur)</td></tr><tr><td><a href="http://www.baiqian.ltd:8080/" target="_blank" rel="noopener noreferrer">http://www.baiqian.ltd:8080/</a></td><td><a href="http://www.baiqian.ltd:7001/" target="_blank" rel="noopener noreferrer">http://www.baiqian.ltd:7001/</a></td><td>跨域</td><td>端口号不同(8080/7001)</td></tr></tbody></table>
|
|
|
|
|
<h2 class="anchor anchorWithHideOnScrollNavbar_WYt5" id="163-什么是-cors">16.3 什么是 CORS<a href="#163-什么是-cors" class="hash-link" aria-label="Direct link to 16.3 什么是 CORS" title="Direct link to 16.3 什么是 CORS"></a></h2>
|
|
|
|
|
<p>跨源资源共享 (<code>CORS</code>) :</p>
|
|
|
|
|
<ul>
|
|
|
|
|
<li>是一种 <code>W3C</code> 标准,可让服务器放宽相同的源策略。</li>
|
|
|
|
|
<li>不是一项安全功能,<code>CORS</code> 放宽 <code>security</code>。 <code>API</code> 不能通过允许 <code>CORS</code> 来更安全。 有关详细信息,请参阅 <a href="https://docs.microsoft.com/zh-cn/aspnet/core/security/cors?view=aspnetcore-5.0#how-cors" target="_blank" rel="noopener noreferrer">CORS 工作原理</a>。</li>
|
|
|
|
|
<li>允许服务器明确允许一些跨源请求,同时拒绝其他请求。</li>
|
|
|
|
|
<li>比早期的技术(如 <code>JSONP</code>)更安全且更灵活。</li>
|
|
|
|
|
</ul>
|
|
|
|
|
<h2 class="anchor anchorWithHideOnScrollNavbar_WYt5" id="164-如何使用">16.4 如何使用<a href="#164-如何使用" class="hash-link" aria-label="Direct link to 16.4 如何使用" title="Direct link to 16.4 如何使用"></a></h2>
|
|
|
|
|
<h3 class="anchor anchorWithHideOnScrollNavbar_WYt5" id="1641-添加-cors-服务">16.4.1 添加 <code>CORS</code> 服务<a href="#1641-添加-cors-服务" class="hash-link" aria-label="Direct link to 1641-添加-cors-服务" title="Direct link to 1641-添加-cors-服务"></a></h3>
|
|
|
|
|
<p>启用跨域 <code>Cors</code> 支持 |