Các lượt nộp
    Danh sách bài
    Trang chủ
    Báo lỗi

    solution

    Đề bài: [Lập trình Web & Backend] Luồng preflight đầy đủ với kiểm tra

    Luồng Preflight Đầy Đủ

    Xử lý một preflight OPTIONS. Server có whitelist origin, danh sách method cho phép, danh sách header cho phép. Trình duyệt gửi Origin, Access-Control-Request-Method, Access-Control-Request-Headers (có thể rỗng).

    Thứ tự kiểm tra (in cảnh báo đầu tiên gặp):

    1. Origin không trong whitelist → BLOCK origin.
    2. Request-Method không trong danh sách method → BLOCK method.
    3. Có header yêu cầu không nằm danh sách header cho phép → BLOCK header <tên-đầu-tiên-bị-từ-chối> (dạng gốc đã trim).
    4. Hợp lệ → in 3 dòng:
    Access-Control-Allow-Origin: <origin>
    Access-Control-Allow-Methods: <method-yêu-cầu>
    Access-Control-Allow-Headers: <danh-sách-header-yêu-cầu nối bằng ', '>
    

    Nếu không có header yêu cầu nào, dòng thứ 3 in Access-Control-Allow-Headers: -.

    Input:

    • Dòng 1: số n whitelist; n dòng.
    • Dòng kế: methods cho phép (phẩy).
    • Dòng kế: headers cho phép (phẩy).
    • Dòng kế: origin.
    • Dòng kế: request-method.
    • Dòng kế: request-headers (phẩy, có thể là dòng rỗng).

    Ví dụ

    Input:

    1
    https://a.com
    GET,POST,PUT
    Content-Type,Authorization
    https://a.com
    PUT
    Content-Type
    

    Output:

    Access-Control-Allow-Origin: https://a.com
    Access-Control-Allow-Methods: PUT
    Access-Control-Allow-Headers: Content-Type
    
    • Định dạng đầu vào:

      n+whitelist / methods / headers / origin / req-method / req-headers.

    • Ràng buộc đầu vào:

      1 ≤ n ≤ 50.

    • Định dạng đầu ra:

      BLOCK ... hoặc 3 dòng header.

    Ví dụ:

    Đầu vào:

    1
    https://a.com
    GET,POST,PUT
    Content-Type,Authorization
    https://a.com
    PUT
    Content-Type
    

    Đầu ra:

    Access-Control-Allow-Origin: https://a.com
    Access-Control-Allow-Methods: PUT
    Access-Control-Allow-Headers: Content-Type

    Giải thích:

    Origin, method PUT và header Content-Type đều hợp lệ nên trả đủ 3 header preflight.

    Đang tải editor...