2016-12-30 50 views
1

当我发出一个请求时,服务器给我提供以下错误:'XMLHttpRequest无法加载http://localhost/pets2homeback/public/register。在预检响应中,访问控制 - 允许 - 标题不允许请求标头字段X-XSRF-TOKEN。 我跟着你的帖子,我无法在Access-Control-Allow-Headers中允许这个X-XSRF-TOKEN,但我并不真正理解这个问题,因为路由是一个寄存器,所以没有令牌,我真的不知道问题出在哪里。不允许在标题中使用X-XSRF-TOKEN Laravel 5.3 + Angular2

这是我kernel.php(重要点)

protected $middleware = [ 
\Illuminate\Foundation\Http\Middleware\CheckForMaintenanceMode::class, 
\Illuminate\Foundation\Http\Middleware\CheckForMaintenanceMode::class, 
\App\Http\Middleware\EncryptCookies::class, 
\Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse::class, 
\Illuminate\Session\Middleware\StartSession::class, 
\Illuminate\View\Middleware\ShareErrorsFromSession::class, 
\App\Http\Middleware\Cors::class, 
\App\Http\Middleware\VerifyCsrfToken::class]; 

这是我cors.php

/** 
* Handle an incoming request. 
* 
* @param \Illuminate\Http\Request $request 
* @param \Closure $next 
* @return mixed 
*/ 
public function handle($request, Closure $next) 
{ 
    return $next($request) 
     ->header("Access-Control-Allow-Origin","*") 
     ->header('Access-Control-Allow-Headers', '*') 
     ->header('Allow', 'GET, POST, PUT, DELETE, OPTIONS') 
     ->header('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS'); 
} 

}

,这是我的routes.php文件(在Laravel 5.3 is web.php)

header('Access-Control-Allow-Origin','http://localhost'); 
header('Access-Control-Allow-Credentials', 'true'); 
Route::get('/', '[email protected]'); 
Route::post('/login', [ 'uses' => '[email protected]']); 
Route::post('/register', [ 'uses' => '[email protected]']); 

这是我在Angular2中的服务。

register(input){ 
let params = JSON.stringify(input); 
let headers = new Headers({'Content-Type':'application/x-www-form-urlencoded; charset=UTF-8'}); 
return this._http.post(this.url+"register", params,{headers: headers}) 
    .map(res => res.json()) 

}

回答

1

我也陷入了同样的问题。不是Laravel,而是PHP背景。

什么解决了我的问题是这样定义的标题:

header('Access-Control-Allow-Headers: Content-Type, x-xsrf-token, x_csrftoken'); 

角仅使用XSRF-Token,但不知何故,我不得不定义这两个。

希望它有帮助。