1234567891011121314151617181920212223242526272829 |
- <?php
- namespace App\Http\Middleware;
- use Closure;
- class EnableCrossRequestMiddleware{
- /**
- * @param $request
- * @param Closure $next
- * @return mixed
- */
- public function handle($request, Closure $next)
- {
- $response = $next($request);
- $origin = $request->server('HTTP_ORIGIN') ? $request->server('HTTP_ORIGIN') : '';
- $allow_origin = [
- 'http://test.com',//允许访问
- ];
- // if (in_array($origin, $allow_origin)) {
- if($response){
- $response->header('Access-Control-Allow-Origin', '*');
- $response->header('Access-Control-Allow-Headers', 'Origin, Content-Type, Cookie, X-CSRF-TOKEN, Accept, Authorization, accessToken, X-XSRF-TOKEN');
- $response->header('Access-Control-Expose-Headers', 'Authorization, authenticated');
- $response->header('Access-Control-Allow-Methods', 'GET, POST, PATCH, PUT, OPTIONS');
- $response->header('Access-Control-Allow-Credentials', 'true');
- }
- // }
- return $response;
- }
- }
|