【问题标题】:Enable CORS in Golang callback function在 Golang 回调函数中启用 CORS
【发布时间】:2016-04-05 23:45:39
【问题描述】:

我对 Google 的 oAuth2 api 进行了 AJAX 调用,如下所示:

$(document).on('click', '#signup', function() {
  var OAUTHURL        =  'https://accounts.google.com/o/oauth2/auth?';
  var SCOPE           =   'email profile';
  var STATE           =   'profile';
  var REDIRECT_URI    =   'https://localhost:8080/callback';
  var RESPONSE_TYPE   =   'token';
  var CLIENT_ID       =   '554886359117-8icq0dc9halr8rjd6bdtqcmagrdql9lr.apps.googleusercontent.com';
  var _url            =    OAUTHURL + 'scope=' + SCOPE + '&state=' + STATE + '&redirect_uri=' + REDIRECT_URI + '&response_type=' + RESPONSE_TYPE + '&client_id=' + CLIENT_ID;
  $.ajax({
    type: "POST",
    dataType: "text",
    url: _url,
    success: function(response)
    {
        console.log(response.url);
    },
    error: function(error)
    {
        console.log("ERROR: ", error);
    }
  });
});

这应该重定向回在http://localhost/callback 上运行的服务器。

Redirect URIs:  http://localhost:8080/callback
Javascript Origins: http://localhost:8080

我也有如下定义的回调函数:

func init() {
    r := mux.NewRouter()

    r.HandleFunc("/", rootHandler)
    r.HandleFunc("/callback", callbackHandler)
    http.Handle("/", r)
}
func callbackHandler(w http.ResponseWriter, r *http.Request) {
    fmt.Fprint(w, "I am sent back from the server!"+time.Now().Format("Mon, 02 Jan 2006 15:04:05 MST"))
}

在调试模式下一切看起来都很好,除了我从谷歌的 api 得到这个错误:

XMLHttpRequest 无法加载 https://accounts.google.com/o/oauth2/auth?scope=email%20profile&state=profi…d=554886359117-8icq0dc9halr8rjd6bdtqcmagrdql9lr.apps.googleusercontent.com。 请求中不存在“Access-Control-Allow-Origin”标头 资源。因此不允许使用原点“http://localhost:8080” 访问。

我已经稍微调整了一下,但我似乎找不到通过的方式。 对此有什么想法吗?

【问题讨论】:

    标签: javascript ajax go cors


    【解决方案1】:

    就像 Not_a_Golfer 说你的后端没有设置正确的响应头。为了在每种情况下处理 CORS 问题,我制作了这个小 handler 来包装您的路由器,这样您就不必在每个回调中手动设置标头。

    像这样使用它:

    import "github.com/heppu/simple-cors"
    
    func init() {
        r := mux.NewRouter()
        r.HandleFunc("/", rootHandler)
        r.HandleFunc("/callback", callbackHandler)
        http.Handle("/", cors.CORS(r))
    }
    func callbackHandler(w http.ResponseWriter, r *http.Request) {
        fmt.Fprint(w, "I am sent back from the server!"+time.Now().Format("Mon, 02 Jan 2006 15:04:05 MST"))
    }
    

    【讨论】:

      【解决方案2】:

      只需将 CORS 标头添加到您的 callbackHandler:

      // make this configurable via command line flags, env var, or something
      var MyServerName = "https://localhost:8080" 
      
      func callbackHandler(w http.ResponseWriter, r *http.Request) {
          w.Header().Add("Access-Control-Allow-Origin", MyServerName)
      
          fmt.Fprint(w, "I am sent back from the server!"+time.Now().Format("Mon, 02 Jan 2006 15:04:05 MST"))
      }
      

      【讨论】:

      • 我用不同的技巧玩过它,似乎并没有真正解决问题。
      • 我的挑战性问题是,问题是来自我的 AJAX 调用通过网络发送还是我的回调处理程序无法处理来自谷歌的响应?
      猜你喜欢
      • 1970-01-01
      • 2017-01-23
      • 2021-12-05
      • 2016-05-24
      • 1970-01-01
      • 2020-07-04
      • 2021-03-21
      • 1970-01-01
      • 2014-08-18
      相关资源
      最近更新 更多