python network_error ai_generated true

CORS 策略阻止了跨域请求:响应中缺少 'Access-Control-Allow-Origin' 头。

Access to XMLHttpRequest at 'http://api.local/users' from origin 'http://frontend.local' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.

ID: python/flask-cors-no-access-control-allow-origin

其他格式: JSON · Markdown 中文 · English
80%修复率
86%置信度
0证据数
2024-11-05首次发现

版本兼容性

版本状态引入弃用备注
4.0.x active — — —

根因分析

服务器未为来源返回 CORS 头,或 flask-cors 配置的 resources 排除了该路径。

English

Server did not return CORS headers for the origin, or flask-cors was configured with resources that exclude the path.

generic

解决方案

  1. 95% 成功率
    from flask_cors import CORS
    CORS(app, resources={r"/api/*": {"origins": "https://frontend.local"}}, supports_credentials=True)
  2. 90% 成功率
    Ensure `@app.after_request` adds headers even on error: def add_cors(resp): resp.headers['Access-Control-Allow-Origin']=origin; return resp

无效尝试

常见但无效的做法:

  1. 80% 失败

    Fails with credentials=true; browsers reject wildcard with credentials.

  2. 75% 失败

    Error responses (4xx/5xx) still lack headers; browser blocks them.