请求头字段访问控制允许来源是不允许

问题描述:

我使用PHP发展RESTFul API。例如下面的代码是针对一个如果这些APIs:请求头字段访问控制允许来源是不允许

<?php 

    require('includes/config.php'); 

     $data = array(); 

     try { 
       $stmt = $db->query('SELECT postID, postTitle, postDesc, postDate,tags FROM blog_posts where inMain=inMain ORDER BY postID DESC LIMIT 5'); 
       $error = false; 
       $message = "ok"; 
       $i=0; 
       while($row = $stmt->fetch()){ 

        $tags = explode(",",$row['tags']); 
        $finalTags = array();   
        foreach($tags as $item) { 
         if($item != '' && $item != ' '){ 
          array_push($finalTags,strtolower(trim($item))); 
         } 
        } 

        array_push($data, [ 
         'id' => $row['postID'], 
         'title' => $row['postTitle'], 
         'desc' => $row['postDesc'], 
         'date' => $row['postDate'], 
         'tags' => $finalTags 
        ]); 

       } 
      } catch(PDOException $e) { 
       $message = $e->getMessage(); 
       $error = true; 
      } 
    $response = array(); 
    $response["data"] = $data; 
    $response["error"] = $error; 
    $response["message"] = $message; 

header('Access-Control-Allow-Origin: *'); 
header('Access-Control-Allow-Credentials: true'); 
header('Access-Control-Allow-Methods: GET,HEAD,OPTIONS,POST,PUT'); 
header('Access-Control-Allow-Headers: Access-Control-Allow-Headers, Origin,Accept, X-Requested-With, Content-Type, Access-Control-Request-Method, Access-Control-Request-Headers'); 
header('Content-Type: application/json'); 

echo json_encode($response); 
?> 

从浏览器调用这个API它工作正常。但是当我把它从我的JavaScript得到以下错误:

​​

我试图调用从AngularJs这个API如下:

app.factory("Data", ['$http', 'toaster', 
    function ($http, toaster) { // This service connects to our REST API 

     var serviceBase = 'http://www.example/v1/'; 
     var conf= { headers: { 
      'Access-Control-Allow-Origin':'*', 
      'Access-Control-Allow-Methods': 'GET, POST, PATCH, PUT, DELETE, OPTIONS', 
      'Access-Control-Allow-Headers': 'Origin, Content-Type, X-Auth-Token', 
      'Content-Type': 'application/json' 
     } 
     }; 

     var obj = {}; 
     obj.toast = function (data) { 

      toaster.pop(data.status, "", data.message, 10000, 'trustedHtml'); 
     } 
     obj.get = function (q) { 
      return $http.get(serviceBase + q,conf).then(function (results) { 
       return results.data; 
      }); 
     }; 
     obj.post = function (q, object) { 
       return $http.post(serviceBase + q, object, conf).then(function (results) { 
       return results.data; 
      }); 
     }; 
     return obj; 
}]); 

有什么问题吗?因为您可以在请求和响应中设置所需的标题?它与托管我使用?

服务器(PHP)也需要允许CORS。将以下标题添加到PHP脚本的开头:

header("Access-Control-Allow-Origin: *"); 
+0

我已经做了。请参阅上面附上的代码 –

+0

标题必须在从服务器发送任何输出之前。所以,它应该在require('includes/config.php')之前。 – Olantobi