python
network_error
ai_generated
true
预检响应未通过访问控制:当请求的credentials模式为'include'时,'Access-Control-Allow-Origin'响应头不能为通配符'*'。
Response to preflight request doesn't pass access control check: The value of the 'Access-Control-Allow-Origin' header in the response must not be the wildcard '*' when the request's credentials mode is 'include'.
ID: python/fastapi-cors-preflight-credentials
80%修复率
88%置信度
0证据数
2024-09-21首次发现
版本兼容性
| 版本 | 状态 | 引入 | 弃用 | 备注 |
|---|---|---|---|---|
| 0.100.x | active | — | — | — |
| 0.110.x | active | — | — | — |
根因分析
CORSMiddleware同时配置了allow_origins=['*']和allow_credentials=True。
English
CORSMiddleware configured with allow_origins=['*'] and allow_credentials=True simultaneously.
解决方案
-
95% 成功率
app.add_middleware(CORSMiddleware, allow_origins=['https://app.example.com'], allow_credentials=True)
-
92% 成功率
app.add_middleware(CORSMiddleware, allow_origin_regex=r'https://.*\.example\.com', allow_credentials=True)
无效尝试
常见但无效的做法:
-
70% 失败
Breaks cookie/auth flows that require credentials.
-
85% 失败
Browsers still enforce the CORS check client-side.