|
|
@@ -9,7 +9,13 @@ use think\Response;
|
|
|
*/
|
|
|
class Cors
|
|
|
{
|
|
|
- public function handle($request, Closure $next)
|
|
|
+ /**
|
|
|
+ * 生成统一的跨域响应头。
|
|
|
+ *
|
|
|
+ * 除中间件正常响应外,shutdown() 这类提前终止的响应也需要复用,
|
|
|
+ * 否则浏览器会把真实的登录/权限错误误报为 CORS 错误。
|
|
|
+ */
|
|
|
+ public static function headers($request): array
|
|
|
{
|
|
|
$origin = $request->header('origin', '');
|
|
|
$origin = trim(str_replace(["\r", "\n"], '', $origin));
|
|
|
@@ -53,6 +59,13 @@ class Cors
|
|
|
$headers['Access-Control-Allow-Private-Network'] = 'true';
|
|
|
}
|
|
|
|
|
|
+ return $headers;
|
|
|
+ }
|
|
|
+
|
|
|
+ public function handle($request, Closure $next)
|
|
|
+ {
|
|
|
+ $headers = self::headers($request);
|
|
|
+
|
|
|
if (strtoupper($request->method()) === 'OPTIONS') {
|
|
|
return Response::create('', 'html', 204)->header($headers);
|
|
|
}
|