Python | Flask solves cross-domain problems

** Python | Flask solves cross-domain problems**

Foreword

Cross domain again

Steps for usage

1. Import library

pip install flask-cors

2. Configuration

flask-cors has two usages, one is for global use, and the other is for specified routes

1. Use CORS function to configure global routing

from flask import Flask, request
from flask_cors import CORS

app =Flask(__name__)CORS(app, supports_credentials=True)

Among them, CORS provides some parameters to help us customize the operation.

For commonly used ones, we can configure origins, methods, allow_headers, supports_credentials

All configuration items are as follows:

: param resources:
 The series of regular expression and(optionally) associated CORS
 options to be applied to the given resource path.

 If the argument is a dictionary, it's keys must be regular expressions,
 and the values must be a dictionary of kwargs, identical to the kwargs
 ofthisfunction.

 If the argument is a list, it is expected to be a list of regular
 expressions,for which the app-wide configured options are applied.

 If the argument is a string, it is expected to be a regular expression
 for which the app-wide configured options are applied.

 Default : Match all and apply app-level configuration

: type resources: dict, iterable or string

: param origins:
 The origin, or list of origins to allow requests from.
 The origin(s) may be regular expressions,case-sensitive strings,
 or else an asterisk

 Default :'*':type origins: list, string or regex

: param methods:
 The method or list of methods which the allowed origins are allowed to
 access for non-simple requests.

 Default :[GET, HEAD, POST, OPTIONS, PUT, PATCH, DELETE]:type methods: list or string

: param expose_headers:
 The header or list which are safe to expose to the API of a CORS API
 specification.

 Default : None
: type expose_headers: list or string

: param allow_headers:
 The header or list of header field names which can be used when this
 resource is accessed by allowed origins. The header(s) may be regular
 expressions,case-sensitive strings, or else an asterisk.

 Default :'*', allow all headers
: type allow_headers: list, string or regex

: param supports_credentials:
 Allows users to make authenticated requests. If true, injects the
 ` Access-Control-Allow-Credentials` header in responses. This allows
 cookies and credentials to be submitted across domains.:note: This option cannot be used in conjuction with a '*' origin

 Default : False
: type supports_credentials: bool

: param max_age:
 The maximum time for which this CORS request maybe cached. This value
 is setas the `Access-Control-Max-Age` header.

 Default : None
: type max_age: timedelta, integer, string or None

: param send_wildcard: If True, and the origins parameter is `*`, a wildcard
 ` Access-Control-Allow-Origin` header is sent, rather than the
 request's `Origin` header.

 Default : False
: type send_wildcard: bool

: param vary_header:
 If True, the header Vary: Origin will be returned as per the W3
 implementation guidelines.

 Setting this header when the `Access-Control-Allow-Origin` is
 dynamically generated(e.g. when there is more than one allowed
 origin, and an Origin than '*' is returned) informs CDNs and other
 caches that the CORS headers are dynamic, and cannot be cached.

 If False, the Vary header will never be injected or altered.

 Default : True
: type vary_header: bool

2. Use @cross_origin to configure single-line routing

from flask import Flask, request
from flask_cors import cross_origin

app =Flask(__name__)

@ app.route('/')
@ cross_origin(supports_credentials=True)
def hello():
 name = request.args.get("name","World")return f'Hello, {name}!'

Among them, cross_origin and CORS provide some basically the same parameters.

For commonly used ones, we can configure origins, methods, allow_headers, supports_credentials

All configuration items are as follows:

: param origins:
 The origin, or list of origins to allow requests from.
 The origin(s) may be regular expressions,case-sensitive strings,
 or else an asterisk

 Default :'*':type origins: list, string or regex

: param methods:
 The method or list of methods which the allowed origins are allowed to
 access for non-simple requests.

 Default :[GET, HEAD, POST, OPTIONS, PUT, PATCH, DELETE]:type methods: list or string

: param expose_headers:
 The header or list which are safe to expose to the API of a CORS API
 specification.

 Default : None
: type expose_headers: list or string

: param allow_headers:
 The header or list of header field names which can be used when this
 resource is accessed by allowed origins. The header(s) may be regular
 expressions,case-sensitive strings, or else an asterisk.

 Default :'*', allow all headers
: type allow_headers: list, string or regex

: param supports_credentials:
 Allows users to make authenticated requests. If true, injects the
 ` Access-Control-Allow-Credentials` header in responses. This allows
 cookies and credentials to be submitted across domains.:note: This option cannot be used in conjuction with a '*' origin

 Default : False
: type supports_credentials: bool

: param max_age:
 The maximum time for which this CORS request maybe cached. This value
 is setas the `Access-Control-Max-Age` header.

 Default : None
: type max_age: timedelta, integer, string or None

: param send_wildcard: If True, and the origins parameter is `*`, a wildcard
 ` Access-Control-Allow-Origin` header is sent, rather than the
 request's `Origin` header.

 Default : False
: type send_wildcard: bool

: param vary_header:
 If True, the header Vary: Origin will be returned as per the W3
 implementation guidelines.

 Setting this header when the `Access-Control-Allow-Origin` is
 dynamically generated(e.g. when there is more than one allowed
 origin, and an Origin than '*' is returned) informs CDNs and other
 caches that the CORS headers are dynamic, and cannot be cached.

 If False, the Vary header will never be injected or altered.

 Default : True
: type vary_header: bool

: param automatic_options:
 Only applies to the `cross_origin` decorator. If True, Flask-CORS will
 override Flask's default OPTIONS handling to return CORS headers for
 OPTIONS requests.

 Default : True
: type automatic_options: bool

Configuration parameter description

Parameter Type Head Default Description
resources Dictionaries, iterators, or strings None All Configure a cross-domain routing interface
origins list, string or regular expression Access-Control-Allow-Origin * Configure the origin that allows cross-domain access
methods list, string Access-Control-Allow-Methods [GET, HEAD, POST, OPTIONS, PUT, PATCH, DELETE] Configure cross-domain support request methods
expose_headers list, string Access-Control-Expose-Headers None Customize the header information of the request response
allow_headers list, string or regular expression Access-Control-Request-Headers * Configure request headers that allow cross-domain
supports_credentials Boolean Access-Control-Allow-Credentials False Whether to allow request to send cookies
max_age timedelta, integer, string Access-Control-Max-Age None Valid duration of preflight request

to sum up

In the cross-domain configuration of flask, we can use flask-cors to configure, where CORS function is used for global configuration, and @cross_origin is used to implement specific routing configuration

Reference

Recommended Posts

Python | Flask solves cross-domain problems
Ubuntu's apt-file solves dependency problems