API:クロスサイト リクエスト

From mediawiki.org
This page is a translated version of the page API:Cross-site requests and the translation is 50% complete.

ユーザー スクリプトやガジェットで別の MediaWiki サイトに対してAPI 呼出しを行う必要がある場合 (たとえば、英語版ウィキペディアのスクリプトが Commons の画像情報を確認する必要がある場合)、JSONP または CORSを使う必要があります。


The API's format=json accepts a callback parameter, whose value is a JavaScript function which the JSON result will be wrapped in. This may be used to call the API on a remote site by dynamically adding ‎<script> tags to the document.

Any JSONP requests will be processed as if logged out (i.e as an anonymous user), even after logging in to the remote wiki.

GET リクエスト


サンプル コード

var apiEndpoint = "https://en.wikipedia.org/w/api.php";
var params = "action=query&list=random&rnlimit=3&format=json";

 * The function to wrap the result
var callback = function (response) {
    var pages = response.query.random; // Process the output to get the titles
    Object.keys(pages).forEach(function(key) {

var scriptTag = document.createElement("script"); // Dynamically create a "script" tag
scriptTag.src = apiEndpoint + "?" + params + "&callback=callback"; // Point to the query string

document.body.appendChild(scriptTag); // Add the script tag to the document


Kache Aye Shoi
Talk:Sarbka, Wągrowiec County
Category:Nakhon Ratchasima Province

CORS の使用

The MediaWiki API requires that the origin be supplied as a query string parameter, with the value being the site from which the request originates, which is matched against the Origin header required by the CORS protocol. Note that this parameter must be included in any pre-flight request, and so should be included in the query string portion of the request URI even for POST requests.

When the origin parameter is supplied and the request does not return a successful CORS response, MediaWiki≥1.30 will return a MediaWiki-CORS-Rejection header with a brief reason for the failure, e.g. in case of mismatched origin or unsupported headers in a Access-Control-Request-Headers request header.

Unauthenticated CORS Requests

Unauthenticated CORS requests may be made from any origin by setting the origin request parameter to *. In this case MediaWiki will include the Access-Control-Allow-Credentials: false header in the response and will process the request as if logged out.

GET リクエスト


サンプル コード

var apiEndpoint = "https://commons.wikimedia.org/w/api.php";
var params = "action=query&list=allimages&ailimit=3&format=json";

 * Send the request to get the images
fetch(apiEndpoint + "?" + params + "&origin=*")
    .then(function(response){return response.json();})
    .then(function(response) {
          var allimages = response.query.allimages; // Process the output to get the image names
          Object.keys(allimages).forEach(function(key) {



Authenticated CORS Requests

To make an authenticated CORS request, the remote wiki's $wgCrossSiteAJAXdomains setting must be set to allow the origin site.

If the CORS origin check passes, MediaWiki will include the Access-Control-Allow-Credentials: true header in the response, so authentication cookies may be sent.

Manual:CORS では、JavaScript で CORS を呼び出す、より多くの手順と例を記しています。


JSONPとCORSの詳細な違いは、CORS vs JSONPで参照可能です。