python
network_error
ai_generated
true
CORS策略阻止:预检请求的响应未通过访问控制检查
Access to fetch at 'http://api.local/x' from origin 'http://web.local' has been blocked by CORS policy: Response to preflight request doesn't pass access control check
ID: python/flask-cors-blocked-preflight
80%修复率
85%置信度
0证据数
2024-12-01首次发现
版本兼容性
| 版本 | 状态 | 引入 | 弃用 | 备注 |
|---|---|---|---|---|
| 4.x | active | — | — | — |
| 5.x | active | — | — | — |
根因分析
Flask-CORS未针对该路由配置,或者OPTIONS预检被CORS中间件之前的catch-all处理。
English
Flask-CORS not configured for the route, or OPTIONS preflight handled by a catch-all before CORS middleware.
解决方案
-
92% 成功率
CORS(app, resources={r'/api/*': {'origins': ['http://web.local']}}, supports_credentials=True) -
90% 成功率
app = Flask(__name__)\nCORS(app)\n# then register blueprints
无效尝试
常见但无效的做法:
-
75% 失败
Preflight OPTIONS never reaches the view; browser blocks it earlier.
-
70% 失败
If credentials used, wildcard origin is rejected by the browser.