我已经在 Heroku的任何地方部署(托管)cors,但我不知道如何自定义它。例如,我想在白名单中添加一个站点链接。我从这个链接获取数据:http: //fmon.asti.dost.gov.ph/dataloc.php?param=rv &dfrm=null&dto=null&numloc=1&data24=1&locs[]=711
我将如何做?我试过触摸 server.js 文件:
// Listen on a specific host via the HOST environment variable
var host = process.env.HOST || '';
// Listen on a specific port via the PORT environment variable
//var port = process.env.PORT || 443;
var port = process.env.PORT || 8080;
// Grab the blacklist from the command-line so that we can update the blacklist without deploying
// again. CORS Anywhere is open by design, and this blacklist is not used, except for countering
// immediate abuse (e.g. denial of service). If you want to block all origins except for some,
// use originWhitelist instead.
var originBlacklist = parseEnvList(process.env.CORSANYWHERE_BLACKLIST);
//var originWhitelist = ['http://fmon.asti.dost.gov.ph/dataloc.php','https://fmon.asti.dost.gov.ph/dataloc.php','http://fmon.asti.dost.gov.ph','https://fmon.asti.dost.gov.ph'];
var originWhitelist = parseEnvList(process.env.CORSANYWHERE_WHITELIST);
function parseEnvList(env) {
if (!env) {
return [];
return env.split(',');
// Set up rate-limiting to avoid abuse of the public CORS Anywhere server.
var checkRateLimit = require('./lib/rate-limit')(process.env.CORSANYWHERE_RATELIMIT);
var cors_proxy = require('./lib/cors-anywhere');
originBlacklist: originBlacklist,
originWhitelist: originWhitelist,
requireHeader: ['origin', 'x-requested-with'],
checkRateLimit: checkRateLimit,
removeHeaders: [
// Strip Heroku-specific headers
redirectSameOrigin: true,
httpProxyOptions: {
// Do not add X-Forwarded-For, etc. headers, because Heroku already adds it.
xfwd: false,
}).listen(port, host, function() {
console.log('Running CORS Anywhere on ' + host + ':' + port);
但是当我访问数据并查看控制台日志时,它会返回一个 403 错误,这是被禁止的。