CORS pre-flight OPTIONS not working because of lowercase casting
还没有人认领这个 Issue。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 35/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- aws, javascript, node.js
调研方向
首先,使用提供的 api.options("/*", ...) 路由重现 OPTIONS 请求,并检查 lambda-api 如何返回已配置的 CORS 标头。跟踪负责将响应标头转换为小写的处理逻辑,然后在 Chrome 中并使用 Postman 验证修正后的预检响应。
由索引模型根据 Issue 内容生成。
描述
Hi all,
I just picked up lambda-api, and seems like its the perfect solution for my project; however, I have been struggling for hours trying to get CORS to work.
My OPTIONS pre-flight request headers are being properly sent, but they're all lower case, and it's causing my web appl running in Google Chrome to not recognize it as Access-Control-Allow-Origin as this is the error I am receiving from it:
Response to preflight request doesn't pass access control check: No 'Access-Control-Allow-Origin' header is present on the requested resource.
I verified, with postman, that this is the headers coming back from the pre-flight OPTIONS request:
However, noticed that they're all lower case, and thus Google Chrome cannot find Access-Control-Allow-Origin
This is how it's getting received in Google Chrome:
This is how I am providing CORS in my Lambda:
// import AWS Lambda types
import { APIGatewayProxyEventV2, Context } from "aws-lambda";
// import Lambda API default function
import createAPI from "lambda-api";
import { Authorizer, Role } from "./authorizer";
import { ListProducts } from "./products/List";
// instantiate framework
const api = createAPI({});
// ************************************* CORS *************************************
api.options("/*", (req: any, res: any) => {
// Add CORS headers
res.header("Access-Control-Allow-Origin", "*");
res.header("Access-Control-Allow-Methods", "*");
res.header("Access-Control-Allow-Headers", "Content-Type, Authorization, Content-Length, X-Requested-With");
res.sendStatus(200);
});
Please suggest a workaround for current version of Chrome.
Thank you!
- 主要语言
- JavaScript
- 星标
- 1.5k
- 派生
- 127
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
jeremydaly/lambda-api 的其他 Issue
-
难度 1/5 1 小时以内 新手友好度 88/100
jeremydaly/lambda-api#356 ·
-
难度 4/5 3-5 天 新手友好度 30/100
jeremydaly/lambda-api#270 ·
-
Logger Output可能重新可做 @naorpeled 于 902 天前认领,目前没有进行中的 PR。 未关闭
jeremydaly/lambda-api#259 · 1 条评论 · 已指派 1 人 ·
-
Is it possible to disable versioning?可能已有人在做 @naorpeled 于 96 天前认领。 未关闭
难度 3/5 1-2 天 新手友好度 52/100
jeremydaly/lambda-api#257 · 5 条评论 ·
-
难度 3/5 1-2 天 新手友好度 38/100
jeremydaly/lambda-api#251 · 1 条评论 ·
查看 jeremydaly/lambda-api 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 82/100
answerLoops/answerLoops#344 ·
维护者通常 1 天内回复
-
Engineering
难度 2/5 1-3 小时 新手友好度 66/100
techmatters/terraso-web-client#3095 ·
-
bug
难度 2/5 1-3 小时 新手友好度 78/100
-
Service process inherits the caller's cwd at first use, holding that folder open on Windows (EBUSY)未关闭
难度 2/5 1-3 小时 新手友好度 76/100
-
难度 2/5 1-3 小时 新手友好度 78/100
nextcloud/viewer#3424 · 1 条评论 ·
维护者通常 1 天内回复