add_header Access-Control-Max-Age 86400;
add_header Access-Control-Allow-Origin *;
add_header Access-Control-Allow-Credentials true;
add_header Access-Control-Allow-Methods GET,PUT,POST,HEAD,PATCH,DELETE,OPTIONS;
add_header Access-Control-Allow-Headers Accept,Accept-Encoding,Accept-Language,Connection,Referer,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type;
add_header Access-Control-Allow-Origin '*';
#add_header Access-Control-Allow-Origin www.xxx.cn,xxx.com,login.xxx.cn;
add_header Access-Control-Allow-Credentials true;
add_header Access-Control-Allow-Headers X-Requested-With;
add_header Access-Control-Allow-Methods '*';
add_header Access-Control-Allow-Headers 'DNT,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Content-Range,Range';
通过curl 查看请求头进行排查
curl --resolve 'www.abc.com:127.0.0.1' https://www.abc.com/ -vvv