gpt4 book ai didi

Nginx : blocked by CORS policy: The 'Access-Control-Allow-Origin' header contains multiple values

转载 作者:行者123 更新时间:2023-12-05 08:05:42 25 4
gpt4 key购买 nike

我需要启用 cors 策略来访问我的 api,我在我的 nginx 服务器文件上做了以下配置:

server {
listen 80 default_server;
listen [::]:80 default_server;

server_name api.domain.com;

location / {

proxy_set_header X-Real-IP $remote_addr;
proxy_set_header Host $host;
proxy_pass http://my_ip:6869/;

set $ref "*";
if ($http_referer ~* ^(http?\:\/\/)(.*?)\/(.*)$) {
set $ref $1$2;
}
add_header 'Access-Control-Allow-Origin' $ref always;
add_header 'Access-Control-Allow-Credentials' 'true' always;
add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE' always;
add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,signature,timestamp' always;
add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range' always;

}

listen [::]:443 ssl ipv6only=on; # managed by Certbot
listen 443 ssl; # managed by Certbot
ssl_certificate /etc/letsencrypt/live/api.domain.com/fullchain.pem; # managed by Certbot
ssl_certificate_key /etc/letsencrypt/live/api.domain.com/privkey.pem; # managed by Certbot
include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot

}

但我不断收到以下错误:

Access to fetch at 'https://api.domain.com/data/key?matches=^art(.*)' from origin 'http://localhost:3500' has been blocked by CORS policy: The 'Access-Control-Allow-Origin' header contains multiple values '*, http://localhost:3500', but only one is allowed. Have the server send the header with a valid value, or, if an opaque response serves your needs, set the request's mode to 'no-cors' to fetch the resource with CORS disabled.

似乎 add_header 正在添加到已设置的 Access-Control-Allow-Origin * header 之上,但我只有这个配置文件,看不到它可能来自的任何其他地方。

有没有办法弄清楚是什么设置了初始 header cors 策略,或者只是覆盖它而不是添加它?

提前谢谢你。

最佳答案

如果您没有正确设置 CORS 配置,就会发生这种情况。您可以使用名为 Allow-Control-Allow-Origin 的插件/扩展在您的本地计算机上修复此问题,并将您的本地主机添加到其中。

另一种方法是在服务器端手动修复配置。

如果您不熟悉 CORS,它基本上用于允许一些跨源请求而拒绝其他请求。例如,如果一个站点提供可嵌入的服务,则可能需要放宽某些限制。

更新

您为 Nginx 使用哪个编译器?如果是 this以下代码之一必须修复它:

location ~* \.(eot|ttf|woff|woff2)$ {
add_header Access-Control-Allow-Origin *;
}

关于Nginx : blocked by CORS policy: The 'Access-Control-Allow-Origin' header contains multiple values,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/63871891/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com