Font from origin 'http://img.***.com' has been blocked from loading by Cross-Origin Resource Sharing policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. Origin 'http://***.com' is therefore not allowed access. The response had HTTP status code 403. (index):1
GET http://img.***.com/wp-content/themes/someone-v2/fonts/fontawesome-webfont.woff
Bereits geladen
location ~* \.(eot|otf|ttf|woff|svg)$ {
add_header Access-Control-Allow-Origin *;
}
font-awesome.min.css:
@font-face{font-family:'FontAwesome';src:url('../fonts/fontawesome-webfont.eot');src:url('../fonts/fontawesome-webfont.eot') format('embedded-opentype'),url('../fonts/fontawesome-webfont.woff') format('woff'),url('../fonts/fontawesome-webfont.ttf') format('truetype'),url('../fonts/fontawesome-webfont.svg') format('svg');font-weight:normal;font-style:normal}
Der Browser kann auf die Symbolschriftart zugreifen und die Seite meldet 403
Wie kann man das durchbrechen?
這個(gè)是因?yàn)槟阍谄吲5目臻g中設(shè)置了防盜鏈,但是防盜鏈中沒(méi)有設(shè)置訪問(wèn)css文件的域名,導(dǎo)致從css文件中訪問(wèn)到的圖片的referer是css的域名,不在防盜鏈的白名單中,所以被403 forbidden了。
目測(cè)還要提供Access-Control-Allow-Methods和Access-Control-Allow-Headers頭