From ec2b78533dc07699ccc7f6d059a74996a330bbee Mon Sep 17 00:00:00 2001 From: "3371392206@qq.com" <3371392206@qq.com> Date: Sun, 16 Aug 2026 18:35:34 +0800 Subject: [PATCH] test: add preflight check test script for cors MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 新增了用于测试CORS预检请求的_node脚本,包含OPTIONS预检请求和实际POST请求的测试逻辑,用于验证接口的跨域配置是否正确。 --- _preflight.js | 53 +++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 53 insertions(+) create mode 100644 _preflight.js diff --git a/_preflight.js b/_preflight.js new file mode 100644 index 0000000..67c4e5d --- /dev/null +++ b/_preflight.js @@ -0,0 +1,53 @@ +const https = require('https'); +const base = 'test-test.zeabur.app'; + +function req(method, path, headers) { + return new Promise((resolve) => { + const r = https.request({ + hostname: base, port: 443, path, method, headers: headers || {}, + }, (res) => { + const chunks = []; + res.on('data', (c) => chunks.push(c)); + res.on('end', () => resolve({ status: res.statusCode, headers: res.headers, body: Buffer.concat(chunks) })); + }); + r.on('error', (e) => resolve({ error: e.message })); + r.end(); + }); +} + +(async () => { + // 1. 预检 OPTIONS 请求 + console.log('=== 预检: OPTIONS /v1/audio/speech (with Origin) ==='); + const r1 = await req('OPTIONS', '/v1/audio/speech', { + 'Origin': 'https://example.com', + 'Access-Control-Request-Method': 'POST', + 'Access-Control-Request-Headers': 'content-type, authorization', + }); + console.log('Status:', r1.status); + console.log('Headers:'); + for (const k of Object.keys(r1.headers)) { + if (k.startsWith('access-control') || k === 'vary') { + console.log(' ' + k + ': ' + r1.headers[k]); + } + } + console.log('Body:', r1.body ? r1.body.toString('utf8') : ''); + + // 2. 预检但无 Origin(同源或非浏览器) + console.log('\n=== OPTIONS /v1/audio/speech (NO Origin) ==='); + const r2 = await req('OPTIONS', '/v1/audio/speech', {}); + console.log('Status:', r2.status); + + // 3. 实际 POST 请求 + console.log('\n=== POST /v1/audio/speech (with Origin) ==='); + const body = JSON.stringify({ model: 'tts-1', input: 'test', voice: 'alloy' }); + const r3 = await req('POST', '/v1/audio/speech', { + 'Origin': 'https://example.com', + 'Content-Type': 'application/json', + 'Authorization': 'Bearer sk-HRNfl15pp8e0KLewaydRCmvf2KfkOYd728yLJmuff5DkyaXd', + 'Content-Length': Buffer.byteLength(body), + }); + if (r3.body) r3.write = r3.write || (() => {}); + console.log('Status:', r3.status); + console.log('Access-Control-Allow-Origin:', r3.headers['access-control-allow-origin']); + console.log('Vary:', r3.headers['vary']); +})();