Files
hldrCenter/server/middleware/cors.go

49 lines
1.4 KiB
Go
Raw Normal View History

2025-10-04 20:48:50 +08:00
package middleware
import (
2025-10-04 21:18:35 +08:00
"fmt"
2025-10-04 20:48:50 +08:00
"net/http"
2025-10-04 21:07:18 +08:00
"github.com/JACKYMYPERSON/hldrCenter/config"
2025-10-04 20:48:50 +08:00
"github.com/gin-gonic/gin"
)
2025-10-04 21:18:35 +08:00
func CorsMiddleware(serverConfig *config.ServerConfig) gin.HandlerFunc {
2025-10-04 20:48:50 +08:00
return func(c *gin.Context) {
2025-10-04 21:18:35 +08:00
// 1. 打印配置的允许源(调试用,确认配置是否正确加载)
fmt.Printf("允许的前端源:%v\n", serverConfig.AllowedOrigins)
// 2. 获取请求的Origin头
2025-10-04 20:48:50 +08:00
origin := c.Request.Header.Get("Origin")
2025-10-04 21:18:35 +08:00
fmt.Printf("当前请求源:%s\n", origin) // 调试用
// 3. 宽松的跨域匹配逻辑
allowOrigin := ""
if len(serverConfig.AllowedOrigins) > 0 {
for _, allowed := range serverConfig.AllowedOrigins {
// 支持通配符*,或精确匹配
if allowed == "*" || allowed == origin {
allowOrigin = origin
break
}
}
2025-10-04 20:48:50 +08:00
}
2025-10-04 21:18:35 +08:00
if allowOrigin != "" {
c.Writer.Header().Set("Access-Control-Allow-Origin", allowOrigin)
}
2025-10-04 20:48:50 +08:00
c.Writer.Header().Set("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE, OPTIONS")
2025-10-04 21:18:35 +08:00
c.Writer.Header().Set("Access-Control-Allow-Headers", "Origin, Content-Type, Accept, Authorization")
2025-10-04 20:48:50 +08:00
c.Writer.Header().Set("Access-Control-Allow-Credentials", "true")
2025-10-04 21:18:35 +08:00
c.Writer.Header().Set("Access-Control-Max-Age", "86400") // 24小时缓存预检请求
2025-10-04 20:48:50 +08:00
2025-10-04 21:18:35 +08:00
// 6. 处理OPTIONS预检请求
2025-10-04 20:48:50 +08:00
if c.Request.Method == "OPTIONS" {
2025-10-04 21:18:35 +08:00
c.AbortWithStatus(http.StatusNoContent) // 使用204更规范
2025-10-04 20:48:50 +08:00
return
}
c.Next()
}
}