如果没有解决方案,访问控制 - 允许原素不允许来源



我试图从10天以上来解决以下问题。我在没有解决方案的情况下将所有指南和页面红色。我使用Java的Jersey库开发了REST Web服务器。服务的结果是JSON格式。在我的服务器中,我添加了CORS过滤器

服务器

package server;
import java.io.IOException;
import javax.ws.rs.container.ContainerRequestContext;
import javax.ws.rs.container.ContainerResponseContext;
import javax.ws.rs.container.ContainerResponseFilter;
public class CORSFilter implements ContainerResponseFilter {
   @Override
   public void filter(final ContainerRequestContext requestContext,
                      final ContainerResponseContext cres) throws IOException {
      cres.getHeaders().add("Access-Control-Allow-Origin", "*");
      cres.getHeaders().add("Access-Control-Allow-Headers", "origin, content-type, accept, authorization");
      cres.getHeaders().add("Access-Control-Allow-Credentials", "true");
      cres.getHeaders().add("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE, OPTIONS, HEAD");
      cres.getHeaders().add("Access-Control-Max-Age", "1209600");
   }
}

和web.xml是:

<?xml version="1.0" encoding="UTF-8"?>
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"     xmlns="http://xmlns.jcp.org/xml/ns/javaee"     xsi:schemaLocation="http://xmlns.jcp.org/xml/ns/javaee     http://xmlns.jcp.org/xml/ns/javaee/web-app_3_1.xsd" version="3.1">
  <display-name>conferenceServer</display-name>
  <welcome-file-list>
    <welcome-file>index.html</welcome-file>
    <welcome-file>index.htm</welcome-file>
    <welcome-file>index.jsp</welcome-file>
    <welcome-file>default.html</welcome-file>
    <welcome-file>default.htm</welcome-file>
    <welcome-file>default.jsp</welcome-file>
  </welcome-file-list>
  <servlet>
        <servlet-name>Jersey REST Service</servlet-name>
        <servlet-    class>org.glassfish.jersey.servlet.ServletContainer</servlet-class>
        <init-param>
            <param-name>jersey.config.server.provider.packages</param-name>
            <param-value>server</param-value>
        </init-param>
        <init-param>
            <param-    name>javax.ws.rs.container.ContainerResponseFilter</param-name>
            <param-value>server.CORSFilter</param-value>
        </init-param>
        <load-on-startup>1</load-on-startup>
    </servlet>
    <servlet-mapping>
        <servlet-name>Jersey REST Service</servlet-name>
        <url-pattern>/*</url-pattern>
    </servlet-mapping>
</web-app>

响应的JSON格式是有效的,但是当我在应用程序中调用服务时,我会收到此消息错误:

[Error] Failed to load resource: Origin http://localhost:8100 is not allowed by Access-Control-Allow-Origin. (all, line 0)
[Error] XMLHttpRequest cannot load http://****/myServer/service. Origin http://localhost:8100 is not allowed by Access-Control-Allow-Origin. 

您认为问题在哪里?

我不认为这可以用作param-name

<param-name>javax.ws.rs.container.ContainerResponseFilter</param-name>

您可以做两件事以确保过滤器已注册:

  1. 在过滤器类的顶部添加@Provider。init-param

    jersey.config.server.provider.packages
    

    将确保从包装扫描中拾取并注册。

  2. 使用Init-Param ...classnames注册过滤器

    <init-param>
        <param-name>jersey.config.server.provider.classnames</param-name>
        <param-value>server.CORSFilter</param-value>
    </init-param>
    

最新更新