teratail header banner
teratail header banner
質問するログイン新規登録

質問編集履歴

1

'Access-Control-Allow-Origin'を削りましたが、実行結果としては同じ結果になりました。

2016/06/07 08:18

投稿

yohira0616
yohira0616

スコア257

title CHANGED
File without changes
body CHANGED
@@ -8,6 +8,40 @@
8
8
  XMLHttpRequest cannot load "https://awesome-api.server.com/api/login" Request header field Access-Control-Allow-Origin is not allowed by Access-Control-Allow-Headers in preflight response.
9
9
  ```
10
10
 
11
+ chromeのNetworkタブの通信結果はこんな感じです
12
+
13
+ **General**
14
+ Request URL:https://awesome-api.server.com/api/login
15
+ Request Method:OPTIONS
16
+ Status Code:200 OK
17
+ Remote Address:(情報保護のため伏せます)
18
+
19
+ **Response Headers**
20
+ Access-Control-Allow-Headers:Content-Type,X-Amz-Date,Authorization,X-Requested-With,X-Requested-By,X-Api-Key,X-Auth-Token
21
+ Access-Control-Allow-Methods:POST
22
+ Access-Control-Allow-Origin:*
23
+ Connection:keep-alive
24
+ Content-Length:18
25
+ Content-Type:application/json
26
+ Date:Tue, 07 Jun 2016 08:11:49 GMT
27
+ Via:1.1 1595f6e72d977d864a2806ced66554f2.cloudfront.net (CloudFront)
28
+ X-Amz-Cf-Id:eqeMld85btOJMKdiF6BQylYEB-NOlwq36r0hPNqkujHmXlngmOvSfg==
29
+ x-amzn-RequestId:7bdf2fa2-2c87-11e6-8972-9bd51d368f78
30
+ X-Cache:Miss from cloudfront
31
+
32
+ **Request Headers**
33
+ Accept:*/*
34
+ Accept-Encoding:gzip, deflate, sdch, br
35
+ Accept-Language:ja,en-US;q=0.8,en;q=0.6
36
+ Access-Control-Request-Headers:accept, access-control-allow-headers, access-control-allow-methods, content-type
37
+ Access-Control-Request-Method:POST
38
+ Cache-Control:max-age=0
39
+ Connection:keep-alive
40
+ Host:awesome-api.server.com
41
+ Origin:http://localhost:3002
42
+ Referer:http://localhost:3002/
43
+ User-Agent:Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36
44
+
11
45
  ###該当のソースコード
12
46
  ```javascript
13
47
  (function ($,window) {
@@ -20,7 +54,6 @@
20
54
  "access_secret": "foo"
21
55
  },
22
56
  headers:{
23
- 'Access-Control-Allow-Origin':'*',
24
57
  'Access-Control-Allow-Headers':'Content-Type,X-Amz-Date,Authorization,X-Requested-With,X-Requested-By,X-Api-Key,X-Auth-Token,Accept',
25
58
  'Access-Control-Allow-Methods':'GET,POST,OPTIONS',
26
59
  'Content-Type':'application/json'