handlers.go 3.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119
  1. package cors
  2. import (
  3. "net/http"
  4. "strings"
  5. "github.com/wuntsong-org/go-zero-plus/rest/internal/response"
  6. )
  7. const (
  8. allowOrigin = "Access-Control-Allow-Origin"
  9. allOrigins = "*"
  10. allowMethods = "Access-Control-Allow-Methods"
  11. allowHeaders = "Access-Control-Allow-Headers"
  12. allowCredentials = "Access-Control-Allow-Credentials"
  13. exposeHeaders = "Access-Control-Expose-Headers"
  14. requestMethod = "Access-Control-Request-Method"
  15. requestHeaders = "Access-Control-Request-Headers"
  16. allowHeadersVal = "Content-Type, Origin, X-CSRF-Token, Authorization, AccessToken, Token, Range"
  17. exposeHeadersVal = "Content-Length, Access-Control-Allow-Origin, Access-Control-Allow-Headers"
  18. methods = "GET, HEAD, POST, PATCH, PUT, DELETE"
  19. allowTrue = "true"
  20. maxAgeHeader = "Access-Control-Max-Age"
  21. maxAgeHeaderVal = "86400"
  22. varyHeader = "Vary"
  23. originHeader = "Origin"
  24. )
  25. // NotAllowedHandler handles cross domain not allowed requests.
  26. // At most one origin can be specified, other origins are ignored if given, default to be *.
  27. func NotAllowedHandler(fn func(w http.ResponseWriter), origins ...string) http.Handler {
  28. return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
  29. gw := response.NewHeaderOnceResponseWriter(w)
  30. checkAndSetHeaders(gw, r, origins)
  31. if fn != nil {
  32. fn(gw)
  33. }
  34. if r.Method == http.MethodOptions {
  35. gw.WriteHeader(http.StatusNoContent)
  36. } else {
  37. gw.WriteHeader(http.StatusNotFound)
  38. }
  39. })
  40. }
  41. // Middleware returns a middleware that adds CORS headers to the response.
  42. func Middleware(fn func(w http.Header), origins ...string) func(http.HandlerFunc) http.HandlerFunc {
  43. return func(next http.HandlerFunc) http.HandlerFunc {
  44. return func(w http.ResponseWriter, r *http.Request) {
  45. checkAndSetHeaders(w, r, origins)
  46. if fn != nil {
  47. fn(w.Header())
  48. }
  49. if r.Method == http.MethodOptions {
  50. w.WriteHeader(http.StatusNoContent)
  51. } else {
  52. next(w, r)
  53. }
  54. }
  55. }
  56. }
  57. func checkAndSetHeaders(w http.ResponseWriter, r *http.Request, origins []string) {
  58. setVaryHeaders(w, r)
  59. if len(origins) == 0 {
  60. setHeader(w, allOrigins)
  61. return
  62. }
  63. origin := r.Header.Get(originHeader)
  64. if isOriginAllowed(origins, origin) {
  65. setHeader(w, origin)
  66. }
  67. }
  68. func isOriginAllowed(allows []string, origin string) bool {
  69. origin = strings.ToLower(origin)
  70. for _, allow := range allows {
  71. if allow == allOrigins {
  72. return true
  73. }
  74. allow = strings.ToLower(allow)
  75. if origin == allow {
  76. return true
  77. }
  78. if strings.HasSuffix(origin, "."+allow) {
  79. return true
  80. }
  81. }
  82. return false
  83. }
  84. func setHeader(w http.ResponseWriter, origin string) {
  85. header := w.Header()
  86. header.Set(allowOrigin, origin)
  87. header.Set(allowMethods, methods)
  88. header.Set(allowHeaders, allowHeadersVal)
  89. header.Set(exposeHeaders, exposeHeadersVal)
  90. if origin != allOrigins {
  91. header.Set(allowCredentials, allowTrue)
  92. }
  93. header.Set(maxAgeHeader, maxAgeHeaderVal)
  94. }
  95. func setVaryHeaders(w http.ResponseWriter, r *http.Request) {
  96. header := w.Header()
  97. header.Add(varyHeader, originHeader)
  98. if r.Method == http.MethodOptions {
  99. header.Add(varyHeader, requestMethod)
  100. header.Add(varyHeader, requestHeaders)
  101. }
  102. }