handlers.go 3.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111
  1. package cors
  2. import (
  3. "net/http"
  4. "github.com/zeromicro/go-zero/rest/internal/response"
  5. )
  6. const (
  7. allowOrigin = "Access-Control-Allow-Origin"
  8. allOrigins = "*"
  9. allowMethods = "Access-Control-Allow-Methods"
  10. allowHeaders = "Access-Control-Allow-Headers"
  11. allowCredentials = "Access-Control-Allow-Credentials"
  12. exposeHeaders = "Access-Control-Expose-Headers"
  13. requestMethod = "Access-Control-Request-Method"
  14. requestHeaders = "Access-Control-Request-Headers"
  15. allowHeadersVal = "Content-Type, Origin, X-CSRF-Token, Authorization, AccessToken, Token, Range"
  16. exposeHeadersVal = "Content-Length, Access-Control-Allow-Origin, Access-Control-Allow-Headers"
  17. methods = "GET, HEAD, POST, PATCH, PUT, DELETE"
  18. allowTrue = "true"
  19. maxAgeHeader = "Access-Control-Max-Age"
  20. maxAgeHeaderVal = "86400"
  21. varyHeader = "Vary"
  22. originHeader = "Origin"
  23. )
  24. // NotAllowedHandler handles cross domain not allowed requests.
  25. // At most one origin can be specified, other origins are ignored if given, default to be *.
  26. func NotAllowedHandler(fn func(w http.ResponseWriter), origins ...string) http.Handler {
  27. return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
  28. gw := response.NewHeaderOnceResponseWriter(w)
  29. checkAndSetHeaders(gw, r, origins)
  30. if fn != nil {
  31. fn(gw)
  32. }
  33. if r.Method == http.MethodOptions {
  34. gw.WriteHeader(http.StatusNoContent)
  35. } else {
  36. gw.WriteHeader(http.StatusNotFound)
  37. }
  38. })
  39. }
  40. // Middleware returns a middleware that adds CORS headers to the response.
  41. func Middleware(fn func(w http.Header), origins ...string) func(http.HandlerFunc) http.HandlerFunc {
  42. return func(next http.HandlerFunc) http.HandlerFunc {
  43. return func(w http.ResponseWriter, r *http.Request) {
  44. checkAndSetHeaders(w, r, origins)
  45. if fn != nil {
  46. fn(w.Header())
  47. }
  48. if r.Method == http.MethodOptions {
  49. w.WriteHeader(http.StatusNoContent)
  50. } else {
  51. next(w, r)
  52. }
  53. }
  54. }
  55. }
  56. func checkAndSetHeaders(w http.ResponseWriter, r *http.Request, origins []string) {
  57. setVaryHeaders(w, r)
  58. if len(origins) == 0 {
  59. setHeader(w, allOrigins)
  60. return
  61. }
  62. origin := r.Header.Get(originHeader)
  63. if isOriginAllowed(origins, origin) {
  64. setHeader(w, origin)
  65. }
  66. }
  67. func isOriginAllowed(allows []string, origin string) bool {
  68. for _, o := range allows {
  69. if o == allOrigins {
  70. return true
  71. }
  72. if o == origin {
  73. return true
  74. }
  75. }
  76. return false
  77. }
  78. func setHeader(w http.ResponseWriter, origin string) {
  79. header := w.Header()
  80. header.Set(allowOrigin, origin)
  81. header.Set(allowMethods, methods)
  82. header.Set(allowHeaders, allowHeadersVal)
  83. header.Set(exposeHeaders, exposeHeadersVal)
  84. if origin != allOrigins {
  85. header.Set(allowCredentials, allowTrue)
  86. }
  87. header.Set(maxAgeHeader, maxAgeHeaderVal)
  88. }
  89. func setVaryHeaders(w http.ResponseWriter, r *http.Request) {
  90. header := w.Header()
  91. header.Add(varyHeader, originHeader)
  92. if r.Method == http.MethodOptions {
  93. header.Add(varyHeader, requestMethod)
  94. header.Add(varyHeader, requestHeaders)
  95. }
  96. }