2016-12-30 51 views
1

當我發出一個請求時,服務器給我提供以下錯誤:'XMLHttpRequest無法加載http://localhost/pets2homeback/public/register。在預檢響應中,訪問控制 - 允許 - 標題不允許請求標頭字段X-XSRF-TOKEN。 我跟着你的帖子,我無法在Access-Control-Allow-Headers中允許這個X-XSRF-TOKEN,但我並不真正理解這個問題,因爲路由是一個寄存器,所以沒有令牌,我真的不知道問題出在哪裏。不允許在標題中使用X-XSRF-TOKEN Laravel 5.3 + Angular2

這是我kernel.php(重要點)

protected $middleware = [ 
\Illuminate\Foundation\Http\Middleware\CheckForMaintenanceMode::class, 
\Illuminate\Foundation\Http\Middleware\CheckForMaintenanceMode::class, 
\App\Http\Middleware\EncryptCookies::class, 
\Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse::class, 
\Illuminate\Session\Middleware\StartSession::class, 
\Illuminate\View\Middleware\ShareErrorsFromSession::class, 
\App\Http\Middleware\Cors::class, 
\App\Http\Middleware\VerifyCsrfToken::class]; 

這是我cors.php

/** 
* Handle an incoming request. 
* 
* @param \Illuminate\Http\Request $request 
* @param \Closure $next 
* @return mixed 
*/ 
public function handle($request, Closure $next) 
{ 
    return $next($request) 
     ->header("Access-Control-Allow-Origin","*") 
     ->header('Access-Control-Allow-Headers', '*') 
     ->header('Allow', 'GET, POST, PUT, DELETE, OPTIONS') 
     ->header('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS'); 
} 

}

,這是我的routes.php文件(在Laravel 5.3 is web.php)

header('Access-Control-Allow-Origin','http://localhost'); 
header('Access-Control-Allow-Credentials', 'true'); 
Route::get('/', '[email protected]'); 
Route::post('/login', [ 'uses' => '[email protected]']); 
Route::post('/register', [ 'uses' => '[email protected]']); 

這是我在Angular2中的服務。

register(input){ 
let params = JSON.stringify(input); 
let headers = new Headers({'Content-Type':'application/x-www-form-urlencoded; charset=UTF-8'}); 
return this._http.post(this.url+"register", params,{headers: headers}) 
    .map(res => res.json()) 

}

回答

1

我也陷入了同樣的問題。不是Laravel,而是PHP背景。

什麼解決了我的問題是這樣定義的標題:

header('Access-Control-Allow-Headers: Content-Type, x-xsrf-token, x_csrftoken'); 

角僅使用XSRF-Token,但不知何故,我不得不定義這兩個。

希望它有幫助。