我已经有一个用于 jwt 身份验证的 Node/Express 服务器设置,可与我的 Create React App 一起使用。我正在使用 CORS npm 包和简单的中间件app.use(cors());
来解决预期的 CORS 相关问题及其正常工作。
现在我想将 Elasticsearch 和ReactiveSearch添加到我的 React 应用程序中,并试图弄清楚如何克服我的本地 ES 实例的 CORS 问题。
我的第一个猜测是我需要创建一个单独的 searchRoutes.js 文件并实现 ES 在本地工作并与我的 React 应用程序连接所需的任何 CORS 代码?
我一直在关注 ReactiveSearch 的文档(使用 http-proxy-middleware)并且没有任何成功......不断收到这个 CORS 错误:无法加载http://localhost:9200/query-index/_msearch?: Access-Control-Allow-Headers 在预检响应中不允许请求标头字段内容类型。
即使我相信我已经实施了 CORS 预检解决方案
app.options('/autocomplete', cors()); // this is for pre-flight
欢迎任何建议、链接或教程
更新:这是我的 Nodejs index.js(服务器)
require('dotenv').config();
import express from 'express';
import http from 'http';
import bodyParser from 'body-parser';
import morgan from 'morgan';
import mongoose from 'mongoose';
import proxy from 'http-proxy-middleware';
import cors from 'cors';
import compression from 'compression';
// import dotenv from 'dotenv'; // added
import router from './router';
// import { dbConfig } from './config';
// Express app init
const app = express();
// app.options('/query-index', cors()); // this is for pre-flight
/* This is where we specify options for the http-proxy-middleware
* We set the target to appbase.io backend here. You can also
* add your own backend url here */
const options = {
// target: 'https://scalr.api.appbase.io/',
target: 'http://localhost:9200',
changeOrigin: true,
// onProxyReq: (proxyReq, req) => {
// proxyReq.setHeader(
// 'Authorization',
// `Basic ${btoa('cf7QByt5e:d2d60548-82a9-43cc-8b40-93cbbe75c34c')}`
// );
// /* transform the req body back from text */
// const { body } = req;
// if (body) {
// if (typeof body === 'object') {
// proxyReq.write(JSON.stringify(body));
// } else {
// proxyReq.write(body);
// }
// }
// }
};
// Connect MongoDB
mongoose.connect(process.env.MONGODB_URI);
mongoose.set('debug', true);
// middleware
app.use(compression());
app.use(morgan('combined'));
app.use(cors()); // cors middleware
// https://stackoverflow.com/a/38345853/3125823
// Enable CORS from client-side from slatepeak
// app.use((req, res, next) => {
// res.header('Access-Control-Allow-Origin', 'http://localhost:3333', 'http://localhost:9200'); // this can also be a list of urls
// res.header('Access-Control-Allow-Methods', 'OPTIONS, PUT, GET, POST, DELETE');
// res.header('Access-Control-Allow-Headers', 'X-Requested-With, X-Auth-Token, Origin, Content-Type, Accept, Authorization, Access-Control-Allow-Credentials');
// // res.header('Access-Control-Allow-Credentials', 'true');
// next();
// });
app.use(bodyParser.json({ type: '*/*' }));
/* This is how we can extend this logic to do extra stuff before
* sending requests to our backend for example doing verification
* of access tokens or performing some other task */
app.use('/query-index', (req, res, next) => {
const { body } = req;
console.log('Verifying requests ✔', body);
/* After this we call next to tell express to proceed
* to the next middleware function which happens to be our
* proxy middleware */
next();
});
/* Here we proxy all the requests from reactivesearch to our backend */
app.use('/query-index', proxy(options));
app.options('/query-index', cors()); // this is for pre-flight
app.get('/query-index', cors(), function(req, res, next) {
res.json({ msg: 'This is CORS-enabled for route \/query-index'});
});
router(app);
const authPort = process.env.PORT || 3333; // default
const authServer = http.createServer(app);
authServer.listen(authPort);
console.log('Auth Server listening on:', authPort);