Access-Control-Allow-Origin不适用于*

时间:2012-09-27 19:16:33

标签: html5 xmlhttprequest cross-domain cors

我尝试通过XHR2上传文件,服务器给我 OPTIONS

HTTP/1.1 200 OK
Server: nginx/1.0.4
Date: Fri, 28 Sep 2012 13:09:43 GMT
Content-Type: application/json;charset=UTF-8
Connection: Keep-Alive
Allow: OPTIONS, HEAD
Access-Control-Allow-Origin: http://mydomain.com
Access-Control-Allow-Methods: GET, HEAD, POST, PUT, DELETE, TRACE, OPTIONS
Access-Control-Allow-Headers: origin, x-mime-type, x-requested-with, x-file-name, content-type
Cache-Control: max-age=3600
Vary: Accept,Accept-Encoding
Access-Control-Allow-Origin: *
Access-Control-Allow-Headers: Content-Type
Access-Control-Allow-Methods: PUT, GET, POST, DELETE, OPTIONS
Content-Encoding: gzip
Content-Length: 48

但我还是得到了

Origin http://mydomain.com is not allowed by Access-Control-Allow-Origin.

我无法删除重复的标题(由我无法触及的未知过滤器插入)。

我该如何解决?

0 个答案:

没有答案