Browse Source

用户展示特定模块

liuzejian 2 years ago
parent
commit
05580873cc
1 changed files with 12 additions and 5 deletions
  1. 12 5
      app/Http/Middleware/EnabledCrossRequestMiddleware.php

+ 12 - 5
app/Http/Middleware/EnabledCrossRequestMiddleware.php

@@ -13,11 +13,18 @@ class EnableCrossRequestMiddleware
     public function handle($request, Closure $next)
     public function handle($request, Closure $next)
     {
     {
         $response = $next($request);
         $response = $next($request);
-        $response->header('Access-Control-Allow-Origin', '*');
-        $response->header('Access-Control-Allow-Headers', 'Origin, Content-Type, Cookie, X-CSRF-TOKEN, Accept, Authorization, X-XSRF-TOKEN');
-        $response->header('Access-Control-Expose-Headers', 'Authorization, authenticated');
-        $response->header('Access-Control-Allow-Methods', 'GET, POST, PATCH, PUT, OPTIONS');
-        $response->header('Access-Control-Allow-Credentials', 'true');
+        $origin = $request->server('HTTP_ORIGIN') ? $request->server('HTTP_ORIGIN') : '';
+        $allow_origin = [
+            'http://localhost:8000',
+            'http://192.168.0.118:8000'
+        ];
+        if (in_array($origin, $allow_origin)) {
+            $response->header('Access-Control-Allow-Origin', '*');
+            $response->header('Access-Control-Allow-Headers', 'Origin, Content-Type, Cookie, X-CSRF-TOKEN, Accept, Authorization, X-XSRF-TOKEN');
+            $response->header('Access-Control-Expose-Headers', 'Authorization, authenticated');
+            $response->header('Access-Control-Allow-Methods', 'GET, POST, PATCH, PUT, OPTIONS');
+            $response->header('Access-Control-Allow-Credentials', 'true');
+        }
         return $response;
         return $response;
     }
     }
 }
 }