fetch设置mode='cors'无法跨域

发布于 2022-09-03 12:23:16 字数 352 浏览 9 评论 0

我用fetch向后台请求一个数据,后台重定向到另外一个服务器去做权限验证,现在提示

clipboard.png

No 'Access-Control-Allow-Origin' header is present on the requested resource.

改成mode='no-cors'之后,没有这个问题了,但是无法重定向到新的页面,返回的status=0.
有谁对fetch跨域了解的吗?

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(3

葬心 2022-09-10 12:23:16

呵呵,我来说一句吧。
No 'xxx'表示你后台服务器没设cors,当然失败了。
至于你fetch设了mode='no-cors'表示不垮域,可以请求成功,但不好意思,你拿不到服务器返回数据,它被标记了'opaque',请求没发出去请看控制台网络面板,这我不多说

豆芽 2022-09-10 12:23:16

https://developer.mozilla.org...

The mode read-only property of the Request interface contains the mode of the request (e.g., cors, no-cors, cors-with-forced-preflight, same-origin, or navigate.) This is used to determine if cross-origin requests lead to valid responses, and which properties of the response are readable:

same-origin — If a request is made to another origin with this mode set, the result is simply an error. You could use this to ensure that a request is always being made to your origin.
**no-cors — Prevents the method from being anything other than HEAD, GET or POST. If any ServiceWorkers intercept these requests, they may not add or override any headers except for these. In addition, JavaScript may not access any properties of the resulting Response. This ensures that ServiceWorkers do not affect the semantics of the Web and prevents security and privacy issues arising from leaking data across domains.**
cors — Allows cross-origin requests, for example to access various APIs offered by 3rd party vendors. These are expected to adhere to the CORS protocol. Only a limited set of headers are exposed in the Response, but the body is readable.
navigate — A mode for supporting navigation. The navigate value is intended to be used only by HTML navigation. A navigate request is created only while navigating between documents.

设置了no-cors以后就不会发送跨域请求了,所以返回 status=0,因为请求根本没发出去.
正确的做法是
https://developer.mozilla.org...

让你们的服务器开发人员在Http Response 中添加Access-Control-Allow-Origin 头

心碎的声音 2022-09-10 12:23:16

这个页面有个CORS的实验,使用fetch,服务端是一个使用koa的不到10行的程序,你可以参考下,可能有帮助

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文