Closed Jer-X closed 3 years ago
nohost版本: 0.6.4 node版本::v12.18.2 whistle版本:2.6.6
触发步骤:
相关页面请求头信息
General Request URL: http://127.0.0.1:8080/admin.html Referrer Policy: strict-origin-when-cross-origin
Response Headers Connection: keep-alive Content-Length: 87 Content-Type: text/html; charset=utf8 Date: Mon, 08 Feb 2021 07:00:44 GMT WWW-Authenticate: Basic realm=User Login
Request Headers: Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 Accept-Encoding: gzip, deflate, br Accept-Language: zh-CN,zh;q=0.9,en-US;q=0.8,en;q=0.7 Cache-Control: max-age=0 Connection: keep-alive Cookie: _ga=GA1.1.1914157490.1597197896; Hm_lvt_d214947968792b839fd669a4decaaffc=1605233845 Host: 127.0.0.1:8080 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36
初步排查结果:
成功结果:
这个鉴权不能去掉,没有弹出登录框吗,什么浏览器?
nohost版本: 0.6.4 node版本::v12.18.2 whistle版本:2.6.6
触发步骤:
相关页面请求头信息
General Request URL: http://127.0.0.1:8080/admin.html Referrer Policy: strict-origin-when-cross-origin
Response Headers Connection: keep-alive Content-Length: 87 Content-Type: text/html; charset=utf8 Date: Mon, 08 Feb 2021 07:00:44 GMT WWW-Authenticate: Basic realm=User Login
Request Headers: Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9 Accept-Encoding: gzip, deflate, br Accept-Language: zh-CN,zh;q=0.9,en-US;q=0.8,en;q=0.7 Cache-Control: max-age=0 Connection: keep-alive Cookie: _ga=GA1.1.1914157490.1597197896; Hm_lvt_d214947968792b839fd669a4decaaffc=1605233845 Host: 127.0.0.1:8080 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: none Sec-Fetch-User: ?1 Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36
初步排查结果:
成功结果: