API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) · 课时

跨源资源共享(CORS)

在 Nginx 中实施 CORS 策略,为 API 启用安全的跨域请求。

第 2 / 4 课12 个步骤

跨源资源共享(CORS) 是 CoddyKit 上的免费 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 课时。 这是第 2 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

What is CORS?

Imagine you're building a web application. Your frontend (like a React app) runs on app.example.com, but it needs to fetch data from your API running on api.example.com.

This is where Cross-Origin Resource Sharing (CORS) comes in. It's a security feature implemented by web browsers to control how web pages from one origin can request resources from another origin.

The Same-Origin Policy

CORS is a relaxation of the browser's Same-Origin Policy. This policy is a critical security mechanism that prevents a malicious website from reading sensitive data from another site.

  • Origin is defined by the protocol, host, and port.
  • https://app.example.com:443 is different from http://app.example.com:80 or https://api.example.com:443.

Without CORS, browsers would block your frontend from talking to your API because they have different origins.

How CORS Works

When your browser detects a cross-origin request, it adds an Origin header to the request. The server then needs to respond with specific CORS headers to tell the browser it's allowed.

The most important header is Access-Control-Allow-Origin. If this header is present in the server's response and its value matches the client's origin (or is *), the browser allows the request.

Simple vs. Preflight Requests

CORS requests can be categorized into two types:

  • Simple Requests: These are direct GET, HEAD, or POST requests with specific content types (like text/plain). The browser sends them immediately, expecting CORS headers in the response.
  • Preflight Requests: For more complex requests (e.g., PUT, DELETE, custom headers, or specific content types), the browser first sends an OPTIONS request. This 'preflight' checks with the server if the actual request is safe to send.

Nginx for CORS Headers

Since Nginx often acts as a reverse proxy or API gateway, it's the perfect place to manage CORS headers for your backend services. We can use Nginx directives to add the necessary Access-Control-* headers to responses.

The primary directive for this is add_header, which allows us to inject custom HTTP headers into Nginx responses.

Configuring Allow-Origin

Let's configure Nginx to allow requests from a specific origin, https://app.example.com, to your API.

We'll add the Access-Control-Allow-Origin header within a location block that handles your API requests.

server {
  listen 80;
  server_name api.example.com;

  location /api/ {
    add_header 'Access-Control-Allow-Origin' 'https://app.example.com';
    proxy_pass http://backend_api_service;
  }
}

Handling Multiple Origins

What if you have multiple frontends that need to access your API? You can't list multiple origins in Access-Control-Allow-Origin directly. Instead, you can use Nginx's map directive to dynamically set the header based on the incoming Origin header.

http {
  map $http_origin $cors_origin {
    default "";
    "https://app.example.com" "https://app.example.com";
    "https://dev.example.com" "https://dev.example.com";
  }

  server {
    listen 80;
    server_name api.example.com;

    location /api/ {
      if ($cors_origin ~ ".") {
        add_header 'Access-Control-Allow-Origin' $cors_origin;
      }
      proxy_pass http://backend_api_service;
    }
  }
}

Configuring Preflight Requests

For preflight (OPTIONS) requests, the browser expects specific headers in response to its OPTIONS call. Nginx needs to intercept these requests and respond with the appropriate CORS headers, often without proxying to the backend.

server {
  listen 80;
  server_name api.example.com;

  location /api/ {
    # Handle preflight OPTIONS requests
    if ($request_method = 'OPTIONS') {
      add_header 'Access-Control-Allow-Origin' 'https://app.example.com';
      add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE';
      add_header 'Access-Control-Allow-Headers' 'Content-Type, Authorization';
      add_header 'Access-Control-Max-Age' 1728000;
      add_header 'Content-Type' 'text/plain charset=UTF-8';
      add_header 'Content-Length' 0;
      return 204;
    }

    # For actual requests
    add_header 'Access-Control-Allow-Origin' 'https://app.example.com';
    proxy_pass http://backend_api_service;
  }
}

Essential CORS Headers

Beyond Access-Control-Allow-Origin, these headers are crucial for full CORS support:

  • Access-Control-Allow-Methods: Specifies allowed HTTP methods (e.g., GET, POST, PUT).
  • Access-Control-Allow-Headers: Lists headers the client is allowed to send (e.g., Content-Type, Authorization).
  • Access-Control-Allow-Credentials: Set to true if the client can send cookies or HTTP authentication.
  • Access-Control-Max-Age: How long the preflight response can be cached by the browser (in seconds).

Comprehensive CORS Setup

Here's a more complete Nginx configuration snippet that handles both simple and preflight CORS requests, allowing a specific origin to interact with your API, including sending credentials.

server {
  listen 80;
  server_name api.example.com;

  location /api/ {
    set $cors_origin "https://app.example.com"; # Or use map directive

    if ($request_method = 'OPTIONS') {
      add_header 'Access-Control-Allow-Origin' "$cors_origin";
      add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, OPTIONS';
      add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization';
      add_header 'Access-Control-Allow-Credentials' 'true';
      add_header 'Access-Control-Max-Age' 1728000;
      add_header 'Content-Type' 'text/plain charset=UTF-8';
      add_header 'Content-Length' 0;
      return 204;
    }

    add_header 'Access-Control-Allow-Origin' "$cors_origin";
    add_header 'Access-Control-Allow-Credentials' 'true';
    add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, OPTIONS';
    add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization';

    proxy_pass http://backend_api_service;
  }
}

CORS Header Check

Which of the following headers are essential for Nginx to respond correctly to a CORS preflight (OPTIONS) request?

Recap: Nginx CORS

In this lesson, you learned about Cross-Origin Resource Sharing (CORS) and why it's vital for secure web applications. We covered:

  • The Same-Origin Policy and why CORS exists.
  • The difference between simple and preflight requests.
  • How to configure Nginx using add_header and map directives to manage CORS.
  • Key CORS headers like Access-Control-Allow-Origin, Access-Control-Allow-Methods, Access-Control-Allow-Headers, and Access-Control-Max-Age.

Properly configuring CORS in Nginx ensures your frontend applications can securely communicate with your backend APIs across different domains.

免费开始

用 AI 导师学习 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) — 免费

在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。

课程
12
课程
48

常见问题解答

「跨源资源共享(CORS)」课时是免费的吗?

是的 — 「跨源资源共享(CORS)」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 课程的其余内容,请升级到 CoddyKit PRO。 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 课程共包含 4 节课。

「跨源资源共享(CORS)」这节课中我会学到什么?

在 Nginx 中实施 CORS 策略,为 API 启用安全的跨域请求。 你通过在浏览器中直接运行的动手代码来练习 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway),全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 需要有经验吗?

无需任何先前经验。CoddyKit 上的 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 4 节。

「跨源资源共享(CORS)」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 课中编写并运行代码吗?

能。每节 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 使用 Nginx 实现 API 版本管理
  2. 跨源资源共享(CORS)
  3. 使用 Nginx 进行速率限制与流量控制
  4. 基于路径的微服务路由
← 返回 API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)