Rails,请求的资源上没有“ Access-Control-Allow-Origin”标头

时间:2018-07-11 08:39:22

标签: ruby-on-rails oauth ruby-on-rails-5 rails-api

我在Angular上有一些应用程序,它使用服务器Ruby on Rails / oAuth后端。在控制台中注册用户时,出现这些错误。

POST*.herokuapp.com/api/users 500 (Internal Server Error)  *.herokuapp.com/api/users:1 
Failed to load *.herokuapp.com/api/users: No 'Access-Control-Allow-Origin' header is present on the requested resource. Origin '*.herokuapp.com' is therefore not allowed access. The response had HTTP status code 500.   /registration:1 

{
 "isTrusted": true     /auth.ts:95
}

以及其他发生的错误

{"error":"invalid_grant","error_description":"The provided authorization grant is invalid, expired, revoked, does not match the redirection URI used in the authorization request, or was issued to another client."}
Error: Uncaught (in promise): {"error":"invalid_grant","error_description":"The provided authorization grant is invalid, expired, revoked, does not match the redirection URI used in the authorization request, or was issued to another client."}

这是我的应用程序。rb

 require_relative 'boot'
 require 'rails/all'

 # Require the gems listed in Gemfile, including any gems
 # you've limited to :test, :development, or :production.
 Bundler.require(*Rails.groups)

 module Dkeeper
   class Application < Rails::Application
     config.middleware.use Rack::Cors do
       allow do
         origins '*'
         resource '*', headers: :any, methods: [:get, :post, :put, :patch, :delete, :options, :head]
       end
     end
   end
 end

在这里user_controller.rb

class Api::UsersController < ApiController
before_action :find_user, only: [:show, :update, :destroy]

def index
  @users = User.all

if @users.count(:all) > 0
  render
else
  render json: { message: 'No Users Found' }, status: 200
end
end

def show
 render
end

def create
@user = User.new(user_params)

if @user.save
  origin = request.headers['origin']
  ApplicationMailer.registration_confirmation(@user, origin).deliver
  render :show, status: :ok
else
  render json: {
    message: 'Registration failed',
    errors: @user.errors.full_messages
  }, status: 422
end
end

def update
if @user.update(user_params)
  render :show
else
  render json: {
    message: 'Could not update profile',
    errors: @user.errors.full_messages
  }, status: 422
end
end

def destroy
if @user.destroy
  render
else
  render json: {
    message: 'Could not delete user',
    errors: @user.errors.full_messages
  }, status: 422
end
end

def confirm_email
user = User.find_by_confirm_token(params[:id])
if user
  user.update_attribute(:email_confirmed, true)
  render json: {
    message: 'Email address has already confirmed',
    errors: user.errors.full_messages
  }, status: 200
else
  render json: {
    message: 'Email confirmation failed'
  }, status: 422
end
end

private

def user_params
  params.require(:user).permit(:email, :first_name, :last_name, :password, :password_confirmation)
end

def find_user
  @user = User.find(params[:id])
end

end

登录时,该用户已添加到数据库中,但是在控制台中出现错误。

谢谢您的帮助。

1 个答案:

答案 0 :(得分:0)

这是一个CORS错误。您需要在服务器端启用CORS,并在客户端端传递正确的标头。也是google“相同原产地政策”