python
network_error
ai_generated
true
CORS 策略阻止了跨域请求:响应中缺少 'Access-Control-Allow-Origin' 头。
Access to XMLHttpRequest at 'http://api.local/users' from origin 'http://frontend.local' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.
ID: python/flask-cors-no-access-control-allow-origin
80%修复率
86%置信度
0证据数
2024-11-05首次发现
版本兼容性
| 版本 | 状态 | 引入 | 弃用 | 备注 |
|---|---|---|---|---|
| 4.0.x | active | — | — | — |
根因分析
服务器未为来源返回 CORS 头,或 flask-cors 配置的 resources 排除了该路径。
English
Server did not return CORS headers for the origin, or flask-cors was configured with resources that exclude the path.
解决方案
-
95% 成功率
from flask_cors import CORS CORS(app, resources={r"/api/*": {"origins": "https://frontend.local"}}, supports_credentials=True) -
90% 成功率
Ensure `@app.after_request` adds headers even on error: def add_cors(resp): resp.headers['Access-Control-Allow-Origin']=origin; return resp
无效尝试
常见但无效的做法:
-
80% 失败
Fails with credentials=true; browsers reject wildcard with credentials.
-
75% 失败
Error responses (4xx/5xx) still lack headers; browser blocks them.