1,前端页面放在域名根目录,比如,http://www.xuecheng.com/ ,对应的nginx配置:- #门户
- location / {
- alias D:/Z_lhy/SpringCloud/xuecheng_online/www/xc-ui-pc-static-portal/;
- index index.html;
- }
2,前端请求接口路径,在域名后面加一个目录- url : "<strong>http://www.xuecheng.com/api/auth/oauth/token</strong>",//发送请求的地址
复制代码 nginx 对api接口配置- location /api/ {
- add_header 'Access-Control-Allow-Origin' $http_origin;
- add_header 'Access-Control-Allow-Credentials' 'true';
- add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS';
- add_header 'Access-Control-Allow-Headers' 'DNT,Authorization,Accept,Origin,Keep-Alive,User-Agent,X-Mx-ReqToken,X-Data-Type,X-Auth-Token,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range';
- add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range';
- if ($request_method = 'OPTIONS') {
- add_header 'Access-Control-Max-Age' 1728000;
- add_header 'Content-Type' 'text/plain; charset=utf-8';
- add_header 'Content-Length' 0;
- return 204;
- }
- proxy_pass http://apiserver/;
- proxy_set_header Host $host;
- proxy_set_header X-Real-IP $remote_addr;
- proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
- proxy_set_header X-Forwarded-Proto $scheme;
- proxy_connect_timeout 5;
- }
这样配置的话,前端页面在域名下:www.xuecheng.com,而访问的接口则是www.xuecheng.com/api/xxx ,这样就不存在跨域问题了,
其实nginx不配置 Access-Control-Allow-Origin也没事,因为前后端在一个域下了。
前端:- var xhr = new XMLHttpRequest()
- xhr.withCredentials = true
- xhr.open('GET', 'http://localhost:8888/', true)
- xhr.send(null)
复制代码 后端:- Access-Control-Allow-Origin: http://www.abc.com(这里必须域名不能是*)
- Access-Control-Allow-Credentials: true
