2025-11-03 17:23:03 +08:00
|
|
|
|
package cors
|
2025-10-04 20:48:50 +08:00
|
|
|
|
|
|
|
|
|
|
import (
|
2025-10-04 21:18:35 +08:00
|
|
|
|
"fmt"
|
2025-10-04 20:48:50 +08:00
|
|
|
|
"net/http"
|
|
|
|
|
|
|
2025-10-04 21:07:18 +08:00
|
|
|
|
"github.com/JACKYMYPERSON/hldrCenter/config"
|
2025-10-04 20:48:50 +08:00
|
|
|
|
"github.com/gin-gonic/gin"
|
|
|
|
|
|
)
|
|
|
|
|
|
|
2025-10-04 21:18:35 +08:00
|
|
|
|
func CorsMiddleware(serverConfig *config.ServerConfig) gin.HandlerFunc {
|
2025-10-04 20:48:50 +08:00
|
|
|
|
return func(c *gin.Context) {
|
2025-11-04 11:52:15 +08:00
|
|
|
|
// 1. 获取请求的Origin头(跨域请求时浏览器会自动带上)
|
2025-10-04 20:48:50 +08:00
|
|
|
|
origin := c.Request.Header.Get("Origin")
|
2025-10-04 21:18:35 +08:00
|
|
|
|
fmt.Printf("当前请求源:%s\n", origin) // 调试用
|
|
|
|
|
|
|
2025-11-04 11:52:15 +08:00
|
|
|
|
// 2. 确定允许的Origin(核心修正)
|
2025-10-04 21:18:35 +08:00
|
|
|
|
allowOrigin := ""
|
2025-11-01 19:36:39 +08:00
|
|
|
|
hasWildcard := false
|
2025-11-04 11:52:15 +08:00
|
|
|
|
|
|
|
|
|
|
// 检查配置中是否有通配符*
|
2025-11-01 19:36:39 +08:00
|
|
|
|
for _, allowed := range serverConfig.AllowedOrigins {
|
|
|
|
|
|
if allowed == "*" {
|
|
|
|
|
|
hasWildcard = true
|
|
|
|
|
|
break
|
|
|
|
|
|
}
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
if hasWildcard {
|
2025-11-04 11:52:15 +08:00
|
|
|
|
// 若配置了*,且请求有Origin(跨域请求),则动态允许当前Origin
|
|
|
|
|
|
// (解决*与credentials冲突的问题)
|
|
|
|
|
|
if origin != "" {
|
|
|
|
|
|
allowOrigin = origin
|
|
|
|
|
|
}
|
2025-11-01 19:36:39 +08:00
|
|
|
|
} else {
|
2025-11-04 11:52:15 +08:00
|
|
|
|
// 没有*,精确匹配配置的允许源
|
2025-10-04 21:18:35 +08:00
|
|
|
|
for _, allowed := range serverConfig.AllowedOrigins {
|
2025-11-01 19:36:39 +08:00
|
|
|
|
if allowed == origin {
|
2025-10-04 21:18:35 +08:00
|
|
|
|
allowOrigin = origin
|
|
|
|
|
|
break
|
|
|
|
|
|
}
|
|
|
|
|
|
}
|
2025-10-04 20:48:50 +08:00
|
|
|
|
}
|
|
|
|
|
|
|
2025-11-04 11:52:15 +08:00
|
|
|
|
// 3. 设置跨域响应头(仅当确定了允许的Origin时才设置)
|
2025-10-04 21:18:35 +08:00
|
|
|
|
if allowOrigin != "" {
|
|
|
|
|
|
c.Writer.Header().Set("Access-Control-Allow-Origin", allowOrigin)
|
|
|
|
|
|
}
|
2025-11-01 19:36:39 +08:00
|
|
|
|
// 允许的方法(包含上传需要的POST)
|
|
|
|
|
|
c.Writer.Header().Set("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE, OPTIONS, PATCH")
|
2025-11-04 11:52:15 +08:00
|
|
|
|
// 允许的头(包含认证和内容类型)
|
|
|
|
|
|
c.Writer.Header().Set("Access-Control-Allow-Headers", "Origin, Content-Type, Accept, Authorization, X-Requested-With, session_id")
|
|
|
|
|
|
// 允许携带凭证(Cookie等,必须与具体Origin配合)
|
2025-10-04 20:48:50 +08:00
|
|
|
|
c.Writer.Header().Set("Access-Control-Allow-Credentials", "true")
|
2025-11-04 11:52:15 +08:00
|
|
|
|
// 预检请求缓存时间(24小时,减少OPTIONS请求次数)
|
2025-11-01 19:36:39 +08:00
|
|
|
|
c.Writer.Header().Set("Access-Control-Max-Age", "86400")
|
2025-10-04 20:48:50 +08:00
|
|
|
|
|
2025-11-01 19:36:39 +08:00
|
|
|
|
// 4. 处理OPTIONS预检请求(上传文件前浏览器会先发这个请求)
|
2025-10-04 20:48:50 +08:00
|
|
|
|
if c.Request.Method == "OPTIONS" {
|
2025-11-04 11:52:15 +08:00
|
|
|
|
fmt.Println("收到OPTIONS预检请求,返回204")
|
2025-11-01 19:36:39 +08:00
|
|
|
|
c.AbortWithStatus(http.StatusNoContent)
|
2025-10-04 20:48:50 +08:00
|
|
|
|
return
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
c.Next()
|
|
|
|
|
|
}
|
|
|
|
|
|
}
|