質問編集履歴
1
'Access-Control-Allow-Origin'を削りましたが、実行結果としては同じ結果になりました。
title
CHANGED
File without changes
|
body
CHANGED
@@ -8,6 +8,40 @@
|
|
8
8
|
XMLHttpRequest cannot load "https://awesome-api.server.com/api/login" Request header field Access-Control-Allow-Origin is not allowed by Access-Control-Allow-Headers in preflight response.
|
9
9
|
```
|
10
10
|
|
11
|
+
chromeのNetworkタブの通信結果はこんな感じです
|
12
|
+
|
13
|
+
**General**
|
14
|
+
Request URL:https://awesome-api.server.com/api/login
|
15
|
+
Request Method:OPTIONS
|
16
|
+
Status Code:200 OK
|
17
|
+
Remote Address:(情報保護のため伏せます)
|
18
|
+
|
19
|
+
**Response Headers**
|
20
|
+
Access-Control-Allow-Headers:Content-Type,X-Amz-Date,Authorization,X-Requested-With,X-Requested-By,X-Api-Key,X-Auth-Token
|
21
|
+
Access-Control-Allow-Methods:POST
|
22
|
+
Access-Control-Allow-Origin:*
|
23
|
+
Connection:keep-alive
|
24
|
+
Content-Length:18
|
25
|
+
Content-Type:application/json
|
26
|
+
Date:Tue, 07 Jun 2016 08:11:49 GMT
|
27
|
+
Via:1.1 1595f6e72d977d864a2806ced66554f2.cloudfront.net (CloudFront)
|
28
|
+
X-Amz-Cf-Id:eqeMld85btOJMKdiF6BQylYEB-NOlwq36r0hPNqkujHmXlngmOvSfg==
|
29
|
+
x-amzn-RequestId:7bdf2fa2-2c87-11e6-8972-9bd51d368f78
|
30
|
+
X-Cache:Miss from cloudfront
|
31
|
+
|
32
|
+
**Request Headers**
|
33
|
+
Accept:*/*
|
34
|
+
Accept-Encoding:gzip, deflate, sdch, br
|
35
|
+
Accept-Language:ja,en-US;q=0.8,en;q=0.6
|
36
|
+
Access-Control-Request-Headers:accept, access-control-allow-headers, access-control-allow-methods, content-type
|
37
|
+
Access-Control-Request-Method:POST
|
38
|
+
Cache-Control:max-age=0
|
39
|
+
Connection:keep-alive
|
40
|
+
Host:awesome-api.server.com
|
41
|
+
Origin:http://localhost:3002
|
42
|
+
Referer:http://localhost:3002/
|
43
|
+
User-Agent:Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36
|
44
|
+
|
11
45
|
###該当のソースコード
|
12
46
|
```javascript
|
13
47
|
(function ($,window) {
|
@@ -20,7 +54,6 @@
|
|
20
54
|
"access_secret": "foo"
|
21
55
|
},
|
22
56
|
headers:{
|
23
|
-
'Access-Control-Allow-Origin':'*',
|
24
57
|
'Access-Control-Allow-Headers':'Content-Type,X-Amz-Date,Authorization,X-Requested-With,X-Requested-By,X-Api-Key,X-Auth-Token,Accept',
|
25
58
|
'Access-Control-Allow-Methods':'GET,POST,OPTIONS',
|
26
59
|
'Content-Type':'application/json'
|