python network_error ai_generated true

预检响应未通过访问控制:当请求的credentials模式为'include'时,'Access-Control-Allow-Origin'响应头不能为通配符'*'。

Response to preflight request doesn't pass access control check: The value of the 'Access-Control-Allow-Origin' header in the response must not be the wildcard '*' when the request's credentials mode is 'include'.

ID: python/fastapi-cors-preflight-credentials

其他格式: JSON · Markdown 中文 · English
80%修复率
88%置信度
0证据数
2024-09-21首次发现

版本兼容性

版本状态引入弃用备注
0.100.x active — — —
0.110.x active — — —

根因分析

CORSMiddleware同时配置了allow_origins=['*']和allow_credentials=True。

English

CORSMiddleware configured with allow_origins=['*'] and allow_credentials=True simultaneously.

generic

解决方案

  1. 95% 成功率
    app.add_middleware(CORSMiddleware, allow_origins=['https://app.example.com'], allow_credentials=True)
  2. 92% 成功率
    app.add_middleware(CORSMiddleware, allow_origin_regex=r'https://.*\.example\.com', allow_credentials=True)

无效尝试

常见但无效的做法:

  1. 70% 失败

    Breaks cookie/auth flows that require credentials.

  2. 85% 失败

    Browsers still enforce the CORS check client-side.