[CORS] ๐ŸŽฏ CORS ์ •์ฑ…์ด ๋ญ”๊ฐ€์š”?

Mec.D's Blogยท2022๋…„ 6์›” 6์ผ
0
post-thumbnail

๐Ÿ“‹ ๊ธฐ์ˆ  ๋ฉด์ ‘ ํ™ˆ ๋ฐ”๋กœ๊ฐ€๊ธฐ


โฌ› ๊ฐœ๋…

๐Ÿ’ก CORS ์ •์ฑ… (Cross Origin Resource Sharing Policy)

โ‰’ ๊ต์ฐจ ์ถœ์ฒ˜ ๋ฆฌ์†Œ์Šค ๊ณต์œ  ์ •์ฑ…
์„œ๋กœ ๋‹ค๋ฅธ Origin ๊ฐ„์˜ ๋ฆฌ์†Œ์Šค ๊ณต์œ ๋ฅผ ํ—ˆ์šฉํ• ์ง€ ๊ฒฐ์ •ํ•˜๋Š” ์ •์ฑ…์ž…๋‹ˆ๋‹ค.


โฌ› ํŠน์ง•

  1. โฌ› Origin์ด ๋‹ค๋ฅด๋ฉด request header์— ์ฟ ํ‚ค๊ฐ€ ์ž๋™์œผ๋กœ ๋“ค์–ด๊ฐ€์ง€ ์•Š์•„ ๋ณ„๋„์˜ ์„ค์ •์„ ํ•ด์•ผํ•ฉ๋‹ˆ๋‹ค.

    ๋‹ค๋ฅธ ๋„๋ฉ”์ธ ๊ฐ„ ์ฟ ํ‚ค ํ—ˆ์šฉ ์˜ต์…˜

    ๊ตฌ๋ถ„์˜ต์…˜
    ํด๋ผ์ด์–ธํŠธWithCredentials: true
    ์„œ๋ฒ„Access-Control-Allow-Credentials: true

โฌ› Origin์ด๋ž€?

scheme://host:port ๋ฅผ Origin์ด๋ผ๊ณ  ํ•ฉ๋‹ˆ๋‹ค.

ex) https://google.com:443
scheme: https
host: google.com
port: 443


โฌ› ๋ธŒ๋ผ์šฐ์ €์—์„œ CORS๋ฅผ ์ฒ˜๋ฆฌํ•˜๋Š” ์ด์œ 

๋ชจ๋“  ์„œ๋ฒ„๋“ค์ด CORS๋ฅผ ์ธ์ง€ํ•˜๋Š” ๊ฒƒ์€ ์•„๋‹ˆ๊ธฐ ๋•Œ๋ฌธ์—
๋ธŒ๋ผ์šฐ์ €์—์„œ CORS๋ฅผ ์ธ์ง€ํ•˜๊ณ  ๊ฑธ๋Ÿฌ์ฃผ๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

profile
๊ธฐ์ˆ ๋กœ ๋” ๋‚˜์€ ๋ฏธ๋ž˜๋ฅผ ๋””์ž์ธํ•˜๋Š” ๊ฐœ๋ฐœ์ž MEC:D ์ž…๋‹ˆ๋‹ค

0๊ฐœ์˜ ๋Œ“๊ธ€