python network_error ai_generated true

CORS策略阻止:预检请求的响应未通过访问控制检查

Access to fetch at 'http://api.local/x' from origin 'http://web.local' has been blocked by CORS policy: Response to preflight request doesn't pass access control check

ID: python/flask-cors-blocked-preflight

其他格式: JSON · Markdown 中文 · English
80%修复率
85%置信度
0证据数
2024-12-01首次发现

版本兼容性

版本状态引入弃用备注
4.x active — — —
5.x active — — —

根因分析

Flask-CORS未针对该路由配置,或者OPTIONS预检被CORS中间件之前的catch-all处理。

English

Flask-CORS not configured for the route, or OPTIONS preflight handled by a catch-all before CORS middleware.

generic

解决方案

  1. 92% 成功率
    CORS(app, resources={r'/api/*': {'origins': ['http://web.local']}}, supports_credentials=True)
  2. 90% 成功率
    app = Flask(__name__)\nCORS(app)\n# then register blueprints

无效尝试

常见但无效的做法:

  1. 75% 失败

    Preflight OPTIONS never reaches the view; browser blocks it earlier.

  2. 70% 失败

    If credentials used, wildcard origin is rejected by the browser.