Laravel 5 CORS中间件不适用于一组路由

时间:2015-11-02 07:04:15

标签: laravel laravel-5 cross-domain cors middleware

我正在使用cors中间件从其他域中访问json。

这段代码很好用: -

Route::get('api/authenticate', ['middleware' => 'cors', function() {
    return Response::json(array('name' => 'Steve Jobs', 'state' => 'California'));
}]);

但是当我将它应用于: -

Route::group(['prefix' => 'api', 'middleware' => 'cors'], function()
{
    Route::resource('authenticate', 'AuthenticateController', ['only' => ['index']]);
    Route::post('authenticate', 'AuthenticateController@authenticate');
});

它在控制台中给我错误,

No 'Access-Control-Allow-Origin' header is present on the requested resource

我已经添加了Cors中间件,cors.php: -

class Cors
{
/**
 * Handle an incoming request.
 *
 * @param  \Illuminate\Http\Request  $request
 * @param  \Closure  $next
 * @return mixed
 */
public function handle($request, Closure $next)
{
    return $next($request)->header('Access-Control-Allow-Origin', '*')->header('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS');
}
}

请帮忙。感谢。

1 个答案:

答案 0 :(得分:1)

在将JWT发送到标头时,我也尝试为我的解决方案。这就是解决我的情况的原因:

1)在路由中间件中添加cors

protected $routeMiddleware = [
    ...
    'cors' => \App\Http\Middleware\Cors::class,
];

2)在全局Middlewre中添加cors

protected $middleware = [
    ...
    \App\Http\Middleware\Cors::class,
];

3)在Cors中间件app / Http / Middleware / Cors.php中添加自定义Access-Control-Allow-Header

<?php namespace App\Http\Middleware;

use Closure;
use Illuminate\Http\Request;
use Log;

class Cors {
    public function handle($request, Closure $next) {
        Log::info("Using cors for " . $request->url());
        return $next($request)
                ->header('Access-Control-Allow-Origin', '*')
                ->header('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS')
                ->header('Access-Control-Allow-Headers', 'Origin, Content-Type, Accept, Authorization, X-Request-With');// <-- Adding this
    }
}