快轉到主要內容

Cross-Origin Resource Sharing (CORS) 跨來源資源共用錯誤解決方法

·932 字·2 分鐘
Y Cheung
作者
Y Cheung
Blogger, Programer & Traveler.
目錄

最近Y cheung 遇到了兩個典型 CORS error問題,XMLHttpRequest 和 Fetch 請求了跨來源資源被瀏覽器阻擋,記錄一下解決方法。

什麼是Cross-Origin Resource Sharing (CORS) 跨來源資源共用?
#

Cross-Origin Resource Sharing (CORS) is an HTTP-header based mechanism that allows a server to indicate any origins (domain, scheme, or port) other than its own from which a browser should permit loading resources. CORS also relies on a mechanism by which browsers make a “preflight” request to the server hosting the cross-origin resource, in order to check that the server will permit the actual request. In that preflight, the browser sends headers that indicate the HTTP method and headers that will be used in the actual request.

簡單來說,就是當你的站點對別的站點發起資源請求的時候,這個http請求就叫做跨來源HTTP請求(cross-origin HTTP request)。網域(domain)、通訊協定(protocol)或通訊埠(port)不同都視為別的站點。

基於安全考量,你的跨來源資源請求會受到限制。XMLHttpRequest 請求和 Fetch 請求默認遵守同源政策(same-origin policy),也就是Y cheung最近遇到的問題所在。

網頁上一般會遇到CORS錯誤的情況:
#

  • XMLHttpRequest 請求
  • Fetch 請求
  • 加載 Web Fonts
  • 加載 WebGL textures
  • 在canvas中使用drawImage() 圖片或視頻幀
  • 使用了圖片的 CSS shape

了解更多有關於CORS的信息可以參看《MDN Web Docs:Cross-Origin Resource Sharing (CORS)

解決AWS S3上的svg圖片因CORS Error 無法顯示問題
#

網站圖片包括svg圖片都放在AWS S3上,就SVG圖片無法顯示,檢查console找到以下錯誤信息:

chrome display cors error
Access to XMLHttpRequest at ‘https://s3.ap-southeast-1.amazonaws.com/public/icons/icon_select_map.svg' from ‘https://example.com’ has been blocked by CORS policy: No ‘Access-Control-Allow-Origin’ header is prevent on the request resource.

此CORS policy error 觸發了XMLHttpRequest同源政策限制,解決辦法就是在AWS S3上正確設置CORS,參看《AWS S3使用者指南:設定跨來源資源分享 (CORS)》。

解決React fetch 自定义header 请求 CORS Error問題
#

前端 React 用 fetch 發起請求:

 1const headers = {
 2  'Content-Type': 'application/json',
 3  Origin: 'http://google.com',
 4  Accept: '*/*',
 5  'Sec-Fetch-Dest': 'empty',
 6  'Sec-Fetch-Mode': 'cors',
 7  'Sec-Fetch-Site': 'same-origin',
 8  mode: 'cors',
 9};
10
11export const getSummary = params => {
12  const url = new URL(`${API_URL}`);
13  const bodyParam = fiterout(JSON.stringify(params));
14  return fetch(url, {
15    method: 'POST',
16    headers,
17    body: bodyParam,
18  }).then(r => r.json());
19};

由于自定義的請求頭部 header 觸發了 fetch 同源政策限制(Content-Type、Accept等):

chrome display cors error
Access to fetch at ‘http://localhost’ from origin ‘http://localhost:3006’ has been blocked by CORS policy: Request header field mode is not allowed by Access-Control-Allow-Headers in preflight response.

Y Cheung 的解決辦法是在接收請求的endpoint上加上相應的header,例如:

 1<?php
 2if ( isset( $_SERVER['HTTP_ORIGIN'] ) ) {
 3	header( "Access-Control-Allow-Origin: {$_SERVER['HTTP_ORIGIN']}" );
 4	header( 'Access-Control-Allow-Credentials: true' );
 5}
 6if ( $_SERVER['REQUEST_METHOD'] == 'OPTIONS' ) {
 7	if ( isset( $_SERVER['HTTP_ACCESS_CONTROL_REQUEST_METHOD'] ) ) {
 8		header( "Access-Control-Allow-Methods: GET, POST, PUT, DELETE, OPTIONS" );
 9	}
10	if ( isset( $_SERVER['HTTP_ACCESS_CONTROL_REQUEST_HEADERS'] ) ) {
11		header( "Access-Control-Allow-Headers: {$_SERVER['HTTP_ACCESS_CONTROL_REQUEST_HEADERS']}" );
12	}
13}

相關文章

獲取最新惡意爬蟲列表配置 Fail2ban Filter

·873 字·2 分鐘
安裝並設置好 Fail2ban 後(可以參考Y Cheung 之前寫的『Fail2ban 配置 Nginx filter』),可以看到在 /etc/fail2ban/filter.d/nginx-badbots.conf 內容如下: 1# /etc/fail2ban/filter.d/nginx-badbots.conf 2# Fail2Ban configuration file 3# 4# Regexp to catch known spambots and software alike. Please verify 5# that it is your intent to block IPs which were driven by 6# above mentioned bots. 7 8[Definition] 9 10badbotscustom = EmailCollector|WebEMailExtrac|TrackBack/1\.02|sogou music spider|(?:Mozilla/\d+\.\d+ )?Jorgee 11 12badbots = Atomic_Email_Hunter/4\.0|atSpider/1\.0|autoemailspider|bwh3_user_agent|China Local Browse 2\.6|ContactBot/0\.2|ContentSmartz|DataCha0s/2\.0|DBrowse 1\.4b|DBrowse 1\.4d|Demo Bot DOT 16b|Demo Bot Z 16b|DSurf15a 01|DSurf15a 71|DSurf15a 81|DSurf15a VA|EBrowse 1\.4b|Educate Search VxB|EmailSiphon|EmailSpider|EmailWolf 1\.00|ESurf15a 15|ExtractorPro|Franklin Locator 1\.8|FSurf15a 01|Full Web Bot 0416B|Full Web Bot 0516B|Full Web Bot 2816B|Guestbook Auto Submitter|Industry Program 1\.0\.x|ISC Systems iRc Search 2\.1|IUPUI Research Bot v 1\.9a|LARBIN-EXPERIMENTAL \(efp@gmx\.net\)|LetsCrawl\.com/1\.0 \+http\://letscrawl\.com/|Lincoln State Web Browser|LMQueueBot/0\.2|LWP\:\:Simple/5\.803|Mac Finder 1\.0\.xx|MFC Foundation Class Library 4\.0|Microsoft URL Control - 6\.00\.8xxx|Missauga Locate 1\.0\.0|Missigua Locator 1\.9|Missouri College Browse|Mizzu Labs 2\.2|Mo College 1\.9|MVAClient|Mozilla/2\.0 \(compatible; NEWT ActiveX; Win32\)|Mozilla/3\.0 \(compatible; Indy Library\)|Mozilla/3\.0 \(compatible; scan4mail \(advanced version\) http\://www\.peterspages\.net/?scan4mail\)|Mozilla/4\.0 \(compatible; Advanced Email Extractor v2\.xx\)|Mozilla/4\.0 \(compatible; Iplexx Spider/1\.0 http\://www\.iplexx\.at\)|Mozilla/4\.0 \(compatible; MSIE 5\.0; Windows NT; DigExt; DTS Agent|Mozilla/4\.0 efp@gmx\.net|Mozilla/5\.0 \(Version\: xxxx Type\:xx\)|NameOfAgent \(CMS Spider\)|NASA Search 1\.0|Nsauditor/1\.x|PBrowse 1\.4b|PEval 1\.4b|Poirot|Port Huron Labs|Production Bot 0116B|Production Bot 2016B|Production Bot DOT 3016B|Program Shareware 1\.0\.2|PSurf15a 11|PSurf15a 51|PSurf15a VA|psycheclone|RSurf15a 41|RSurf15a 51|RSurf15a 81|searchbot admin@google\.com|ShablastBot 1\.0|snap\.com beta crawler v0|Snapbot/1\.0|Snapbot/1\.0 \(Snap Shots&#44; \+http\://www\.snap\.com\)|sogou develop spider|Sogou Orion spider/3\.0\(\+http\://www\.sogou\.com/docs/help/webmasters\.htm#07\)|sogou spider|Sogou web spider/3\.0\(\+http\://www\.sogou\.com/docs/help/webmasters\.htm#07\)|sohu agent|SSurf15a 11 |TSurf15a 11|Under the Rainbow 2\.2|User-Agent\: Mozilla/4\.0 \(compatible; MSIE 6\.0; Windows NT 5\.1\)|VadixBot|WebVulnCrawl\.unknown/1\.0 libwww-perl/5\.803|Wells Search II|WEP Search 00 13 14failregex = ^<HOST> -.*"(GET|POST|HEAD).*HTTP.*"(?:%(badbots)s|%(badbotscustom)s)"$ 15 16ignoreregex = 17 18datepattern = {^LN-BEG}%%ExY(?P<_sep>[-/.])%%m(?P=_sep)%%d[T ]%%H:%%M:%%S(?:[.,]%%f)?(?:\s*%%z)? 19 ^[^\[]*\[({DATE}) 20 {^LN-BEG} 21 22# DEV Notes: 23# List of bad bots fetched from http://www.user-agents.org 24# Generated on Thu Nov 7 14:23:35 PST 2013 by files/gen_badbots. 25# 26# Author: Yaroslav Halchenko 如果沒有找到這個文件,請新建一個,或者將 apache-badbots.conf 拷貝並重命名。

Fail2ban 配置 Nginx filter

·639 字·2 分鐘
簡要紀錄一下目前服務器上的 fail2ban 關於 nginx 的 filter 配置。 惡意爬蟲過濾器 # 1# /etc/fail2ban/filter.d/nginx-badbots.conf 2[Definition] 3 4badbotscustom = Sogou web spider|DotBot|AhrefsBot|Baiduspider|PetalBot|WOW64|Daum|Barkrowler|360Spider|Buck|Photon|SEOkicks|magpie-crawler|SemrushBot|SeznamBot|MJ12bot|EmailCollector|WebEMailExtrac|TrackBack/1\.02|sogou music spider|(?:Mozilla/\d+\.\d+ )?Jorgee 5 6badbots = Atomic_Email_Hunter/4\.0|atSpider/1\.0|autoemailspider|bwh3_user_agent|China Local Browse 2\.6|ContactBot/0\.2|ContentSmartz|DataCha0s/2\.0|DBrowse 1\.4b|DBrowse 1\.4d|Demo Bot DOT 16b|Demo Bot Z 16b|DSurf15a 01|DSurf15a 71|DSurf15a 81|DSurf15a VA|EBrowse 1\.4b|Educate Search VxB|EmailSiphon|EmailSpider|EmailWolf 1\.00|ESurf15a 15|ExtractorPro|Franklin Locator 1\.8|FSurf15a 01|Full Web Bot 0416B|Full Web Bot 0516B|Full Web Bot 2816B|Guestbook Auto Submitter|Industry Program 1\.0\.x|ISC Systems iRc Search 2\.1|IUPUI Research Bot v 1\.9a|LARBIN-EXPERIMENTAL \(efp@gmx\.net\)|LetsCrawl\.com/1\.0 \+http\://letscrawl\.com/|Lincoln State Web Browser|LMQueueBot/0\.2|LWP\:\:Simple/5\.803|Mac Finder 1\.0\.xx|MFC Foundation Class Library 4\.0|Microsoft URL Control - 6\.00\.8xxx|Missauga Locate 1\.0\.0|Missigua Locator 1\.9|Missouri College Browse|Mizzu Labs 2\.2|Mo College 1\.9|MVAClient|Mozilla/2\.0 \(compatible; NEWT ActiveX; Win32\)|Mozilla/3\.0 \(compatible; Indy Library\)|Mozilla/3\.0 \(compatible; scan4mail \(advanced version\) http\://www\.peterspages\.net/?scan4mail\)|Mozilla/4\.0 \(compatible; Advanced Email Extractor v2\.xx\)|Mozilla/4\.0 \(compatible; Iplexx Spider/1\.0 http\://www\.iplexx\.at\)|Mozilla/4\.0 \(compatible; MSIE 5\.0; Windows NT; DigExt; DTS Agent|Mozilla/4\.0 efp@gmx\.net|Mozilla/5\.0 \(Version\: xxxx Type\:xx\)|NameOfAgent \(CMS Spider\)|NASA Search 1\.0|Nsauditor/1\.x|PBrowse 1\.4b|PEval 1\.4b|Poirot|Port Huron Labs|Production Bot 0116B|Production Bot 2016B|Production Bot DOT 3016B|Program Shareware 1\.0\.2|PSurf15a 11|PSurf15a 51|PSurf15a VA|psycheclone|RSurf15a 41|RSurf15a 51|RSurf15a 81|searchbot admin@google\.com|ShablastBot 1\.0|snap\.com beta crawler v0|Snapbot/1\.0|Snapbot/1\.0 \(Snap Shots&#44; \+http\://www\.snap\.com\)|sogou develop spider|Sogou Orion spider/3\.0\(\+http\://www\.sogou\.com/docs/help/webmasters\.htm#07\)|sogou spider|Sogou web spider/3\.0\(\+http\://www\.sogou\.com/docs/help/webmasters\.htm#07\)|sohu agent|SSurf15a 11 |TSurf15a 11|Under the Rainbow 2\.2|User-Agent\: Mozilla/4\.0 \(compatible; MSIE 6\.0; Windows NT 5\.1\)|VadixBot|WebVulnCrawl\.unknown/1\.0 libwww-perl/5\.803|Wells Search II|WEP Search 00 7 8failregex = ^<HOST> -.*"(GET|POST|HEAD).*HTTP.*"*(?:%(badbots)s|%(badbotscustom)s).*"$ 9 10ignoreregex = 11 12datepattern = {^LN-BEG}%%ExY(?P<_sep>[-/.])%%m(?P=_sep)%%d[T ]%%H:%%M:%%S(?:[.,]%%f)?(?:\s*%%z)? 13 ^[^\[]*\[({DATE}) 14 {^LN-BEG} 15 16/etc/fail2ban/filter.d/nginx-badbots.conf 自定義規則 # 1# /etc/fail2ban/filter.d/nginx-custom.conf 2[Definition] 3failregex = ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+XDEBUG.+$ 4 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+GponForm.+$ 5 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+phpunit.+$ 6 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+ajax-index\.php .+$ 7 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+sellers\.json .+$ 8 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+adminer\.php .+$ 9 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+wp-configuration\.php.+$ 10 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+ThinkPHP.+$ 11 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+wp-config.+$ 12 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+dede\/login\.php .+$ 13 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+plus\/recommend\.php .+$ 14 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+e\/install\/index.php .+$ 15 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+m\/e\/install\/index\.php .+$ 16 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+e_bak\/install\/index.php .+$ 17 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+\.aspx .+$ 18 ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+\.act .+$ 19 ^<HOST>.*] "(GET|POST|HEAD) .*xmlrpc\.php.* 20 ^<HOST> -.*"(GET|POST|HEAD).*HTTP\/1\.1.*"*.Mozilla/5\.0 \(Windows NT 6\.1\; rv\:60\.0\) Gecko\/20100101 Firefox\/60\.0.*"$ 21 ^<HOST> -.*"(GET|POST|HEAD).*HTTP\/1\.1.*"*.Photon.*"$ 22 ^<HOST> -.*"(GET|POST|HEAD).*HTTP\/1\.1.*"*.Mozilla\/5\.0 zgrab\/0\.x.*"$ 23 ^<HOST> -.*"(GET|POST|HEAD).*HTTP\/1\.1.*"*.XTC.*"$ 24 ^<HOST> -.*"(GET|POST|HEAD).*HTTP\/1\.1.*"*.python-requests.*"$ 25 ^<HOST> -.*"(GET|POST|HEAD).*HTTP\/1\.1.*"*.bidswitchbot.*"$ 26 ^<HOST> -.*"(GET|POST|HEAD).*HTTP\/1\.1.*"*.Google-adstxt.*"$ 27 ^<HOST> -.*"(GET|POST|HEAD).*HTTP\/1\.1.*"*.Apache-HttpClient.*"$ 28 ^<HOST>.*] "POST .*HTTP\/1\.1.* 29 ^<HOST> -.*"(GET|POST|HEAD).*HTTP\/1\.1.*"*.Go-http-client\/1\.1.*"$ 30 ^<HOST> .* ".*\\x.*" .*$ 31 ^<HOST> -.*"(GET|POST|HEAD) .+wp-login\.php .*HTTP\/1\.1.* 32 ^<HOST> -.*"(GET|POST|HEAD) .*wp-includes/wlwmanifest.xml .*HTTP\/1\.1.* 33ignoreregex = ^<HOST>.*] "POST /xmlrpc\.php\?for=jetpack.* 34 ^<HOST>.*] "POST /wp-cron\.php\?doing_wp_cron=.* 35datepattern = {^LN-BEG}%%ExY(?P<_sep>[-/.])%%m(?P=_sep)%%d[T ]%%H:%%M:%%S(?:[.,]%%f)?(?:\s*%%z)? 36 ^[^\[]*\[({DATE}) 37 {^LN-BEG} 簡要說明一下:

修復SSL_do_handshake() failed 錯誤

·463 字·1 分鐘
最近WP網站遇到了詭異的問題,Jetpack 的統計數據與 Google Analytics 上的不一致,wordpress.com 面板上又顯示無法訪問這個站點,但是 Y Chueng 用瀏覽器打開網站又正常,很奇怪。然後本應該在昨日計劃發佈的 Post 沒有被發佈。太奇怪了。