Chrome javascript错误:拒绝使用servicestack获取不安全的标头X-Response-Time

时间:2017-08-01 18:11:40

标签: servicestack

我在Chrome控制台中收到此错误。

我将X-Response-Time标头添加到allowedHeaders到CorsFeatures

Plugins.Add(new CorsFeature(
"*",
allowCredentials: true,
allowedHeaders: "Content-Type, Allow, Authorization, X-Response-Time"));

我也将标题添加到响应中,任何想法?

[AddHeader(name: "X-Response-Time",value: "")]

enter image description here

1 个答案:

答案 0 :(得分:1)

我添加了标题Access-Control-Expose-Headers并且有效!

Access-Control-Allow-Credentials:true
Access-Control-Allow-Headers:Content-Type, Allow, Authorization, X-Response-Time
Access-Control-Allow-Methods:GET, POST, PUT, DELETE, PATCH, OPTIONS
Access-Control-Allow-Origin:*
Access-Control-Expose-Headers:Content-Type, Allow, Authorization, X-Response-Time