无法在AngularJS中的请求中指定标头

时间:2013-10-08 12:30:08

标签: javascript ruby-on-rails angularjs cross-domain angular-http

我的应用程序中有2个部分 - Angular前端和rails服务器。并且因为它是不同的域,所以默认情况下请求不起作用。有很多工作人员,包括堆栈,但它不适合我。

这是我在角度控制器中的方法:

$scope.test =->
  # transform = (data) ->
  #   $.param data

  $http.post('http://localhost:3000/session/create', 'token=some',
    headers:
      'Access-Control-Allow-Origin': 'http://localhost:9000',
      'Access-Control-Allow-Methods': 'GET, POST, PUT, DELETE, OPTIONS',
      'Access-Control-Allow-Headers': 'Content-Type, X-Requested-With'
    # transformRequest: transform
  ).success (responseData) ->
    console.log(responseData)

我评论了转换数据,服务器响应没有区别。

我配置了app(在某些帖子中看到了这样):

.config ["$httpProvider", ($httpProvider) ->
  $httpProvider.defaults.useXDomain = true
  delete $httpProvider.defaults.headers.common["X-Requested-With"]
]

我想这会使请求不像ajax(但我不确定)。

但我的请求中没有标题。它们都在某些字段中Access-Control-Request-Headers:access-control-allow-origin, accept, access-control-allow-headers, access-control-allow-methods, content-type

    Request URL:http://localhost:3000/session/create
    Request Method:OPTIONS
    Status Code:404 Not Found

    Request Headers

    Accept:*/*
    Accept-Encoding:gzip,deflate,sdch
    Accept-Language:en-US,en;q=0.8,ru;q=0.6
    Access-Control-Request-Headers:access-control-allow-origin, accept, access-control-allow-headers, access-control-allow-methods, content-type
    Access-Control-Request-Method:POST
    Connection:keep-alive
    DNT:1
    Host:localhost:3000
    Origin:http://localhost:9000
    Referer:http://localhost:9000/
    User-Agent:Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.8 Safari/537.36

    Response Headers

    Content-Length:12365
    Content-Type:text/html; charset=utf-8
    X-Request-Id:2cf4b37b-eb47-432a-ab30-b802b3e33218
    X-Runtime:0.030128

Chrome控制台:

OPTIONS http://localhost:3000/session/create 404 (Not Found) angular.js:6730
OPTIONS http://localhost:3000/session/create No 'Access-Control-Allow-Origin' header is     present on the requested resource. Origin 'http://localhost:9000' is therefore not allowed access. angular.js:6730
XMLHttpRequest cannot load http://localhost:3000/session/create. No 'Access-Control-Allow-Origin' header is present on the requested resource. Origin 'http://localhost:9000' is therefore not allowed access. localhost/:1

其他无关紧要的信息: 在服务器上:

class ApplicationController < ActionController::Base
  before_filter :allow_cross_domain_access

  protected

  def allow_cross_domain_access
    headers['Access-Control-Allow-Origin'] = '*'# http://localhost:9000
    headers['Access-Control-Allow-Headers'] = 'GET, POST, PUT, DELETE'
    headers['Access-Control-Allow-Methods'] = %w{Origin Accept Content-Type X-Requested-With X-CSRF-Token}.join(',')
    headers['Access-Control-Max-Age'] = '1728000'

  end
end

路线显而易见post "session/create"。和会话控制器:

class SessionController < ApplicationController
  respond_to :json, :html, :js

  def create
    respond_with "logged in"
    # render nothing: true
  end
end

我使用角度1.2.0.rc-2的最新版本。 this is my project on github

1 个答案:

答案 0 :(得分:7)

您在示例中混淆了请求和响应标头。

在执行跨域请求(CORS)并且您希望创建与普通GET不同的任何内容时 - 例如POST或添加自定义标头 - 浏览器将首先发出OPTIONS请求。 这是您在开发人员控制台中看到的内容:

OPTIONS http://localhost:3000/session/create 404 (Not Found) angular.js:6730

然后,服务器应将相应的标头添加到OPTIONS请求的响应中。

因此,您可以从Angular调用中删除自定义标头。 接下来,您需要确保您的服务器/应用程序应答OPTIONS请求,而不是返回404。