Javascript Flash Access-Control-Allow-Origin 跨域

来源:互联网 发布:sql server可视化界面 编辑:程序博客网 时间:2024/06/02 13:53
Access-Control-Allow-Origin 是html5 添加的新功能, chrome貌似前几天更新之后支持了这一特性.


基本上, 这是一个http的header, 用在返回资源的时候, 指定这个资源可以被哪些网域跨站访问.


比方说, 你的图片都放在 res.byneil.com 这个域下, 如果在返回的头中没有设置 Access-Control-Allow-Origin , 那么别的域是不能外链你的图片的.


当然这要取决于浏览器的实现是否遵守规范. 因为chrome最近的升级开始检查这个头了, 所以导致一些网站资源加载不进来.


解决方法就是 在资源的头中 加入 Access-Control-Allow-Origin 指定你授权的域. 我这里无所谓,就指定星号 * , 任何域都可以访问我的资源.


Access-Control-Allow-Origin: *
具体操作方法, 就是在nginx的conf文件中加入以下内容:

location / {
  add_header Access-Control-Allow-Origin *;
}

这样就好了.



淘宝的:

<?xml version="1.0" encoding="UTF-8"?>  <cross-domain-policy>      <allow-access-from domain="*.taobao.com" />      <allow-access-from domain="*.taobao.net" />      <allow-access-from domain="*.taobaocdn.com" />      <allow-access-from domain="*.allyes.com" />  </cross-domain-policy> 

<?xml version="1.0" encoding="UTF-8"?><cross-domain-policy><allow-access-from domain="localhost" /><allow-access-from domain="10.16.136.107"/><allow-access-from domain="*.bloomberg.com" /><allow-access-from domain="*.pointroll.com" /><allow-access-from domain="*.pointroll.net" /></cross-domain-policy>


<?xml version="1.0" encoding="UTF-8"?><cross-domain-policy><allow-access-from domain="*.reuters.com" secure="false" /><allow-access-from domain="ad.doubleclick.net"secure="false" /><allow-access-from domain="ad.uk.doubleclick.net"secure="false" /><allow-access-from domain="m.2mdn.net" secure="false" /><allow-access-from domain="m2.2mdn.net" secure="false" /></cross-domain-policy>


<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><site-control permitted-cross-domain-policies="master-only" /><allow-access-from domain="s-static.facebook.com" /><allow-access-from domain="static.facebook.com" /><allow-access-from domain="static.api.ak.facebook.com" /><allow-access-from domain="*.static.ak.facebook.com" /><allow-access-from domain="s-static.thefacebook.com" /><allow-access-from domain="static.thefacebook.com" /><allow-access-from domain="static.api.ak.thefacebook.com" /><allow-access-from domain="*.static.ak.thefacebook.com" /><allow-access-from domain="*.static.ak.fbcdn.com" /><allow-access-from domain="external.ak.fbcdn.com" /><allow-access-from domain="*.static.ak.fbcdn.net" /><allow-access-from domain="external.ak.fbcdn.net" /><allow-access-from domain="www.facebook.com" /><allow-access-from domain="www.new.facebook.com" /><allow-access-from domain="register.facebook.com" /><allow-access-from domain="login.facebook.com" /><allow-access-from domain="ssl.facebook.com" /><allow-access-from domain="secure.facebook.com" /></cross-domain-policy>

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><site-control permitted-cross-domain-policies="by-content-type" /></cross-domain-policy>

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="*" /><allow-http-request-headers-from domain="*" headers="*" /></cross-domain-policy>

1 0