dongyi5425 2014-10-07 21:35
浏览 55

google +登录api,通过http发送访问权限?

Hello unfortunately the site I am working on has no SSL certificate or anything (Kinda stupid but nothing I can do). I am implementing google+ sign in on the site and the JavaScript is all working, I get the access token back and everything as well.

The Problem is when it comes time to send the data off to the server for verification before signing a user in, is it ok to send the access token over HTTP or do I NEED SSL for that. I have tried getting CORS to work with Ajax but I keep getting a

"Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at https://www.mysite.com/Store/google_login. This can be fixed by moving the resource to the same domain or enabling CORS."

It works over over HTTP obviously but I have no idea how to get it working using HTTPS, it just keeps bringing back that same error.

I tried putting these headers at the beginning of the google_login function, even tried it with .httaccess instead and still nothing.

header("Access-Control-Allow-Origin: https://www.mysite.com");
header("Access-Control-Allow-Headers: Cache-Control, X-CSRF-Token, X-Requested-With, X-File-Name, X-File-Size");

So any ideas on what to do? Can I just use HTTP, maybe somehow encrypt it before sending it, I doubt it but I don't know what else to do to get cors working, the server has no SSL certificate by the way, could that be the problem? I have no way to fix that either unfortunately

  • 写回答

0条回答 默认 最新

    报告相同问题?

    悬赏问题

    • ¥15 基于卷积神经网络的声纹识别
    • ¥15 Python中的request,如何使用ssr节点,通过代理requests网页。本人在泰国,需要用大陆ip才能玩网页游戏,合法合规。
    • ¥100 为什么这个恒流源电路不能恒流?
    • ¥15 有偿求跨组件数据流路径图
    • ¥15 写一个方法checkPerson,入参实体类Person,出参布尔值
    • ¥15 我想咨询一下路面纹理三维点云数据处理的一些问题,上传的坐标文件里是怎么对无序点进行编号的,以及xy坐标在处理的时候是进行整体模型分片处理的吗
    • ¥15 CSAPPattacklab
    • ¥15 一直显示正在等待HID—ISP
    • ¥15 Python turtle 画图
    • ¥15 stm32开发clion时遇到的编译问题