You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法在网关到授权服务器的重定向请求中设置Allow Origin头

Spring OAuth2 Client与Spring Authorization Server重定向请求无法设置Access-Control-Allow-Origin问题

我正在学习Spring OAuth2 Client与Spring Authorization Server,遇到一个问题:无法在网关到授权服务器的重定向请求中设置响应头Access-Control-Allow-Origin。授权服务器未配置CORS,以下是网关的相关配置及请求、响应头信息:

CORS配置与安全过滤器链

@Bean
public CorsConfigurationSource corsConfigurationSource() {
    UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
    CorsConfiguration config = new CorsConfiguration();
    config.addAllowedHeader("Access-Control-Allow-Origin");
    config.addAllowedHeader("X-XSRF-TOKEN");
    config.addAllowedHeader(HttpHeaders.CONTENT_TYPE);
    config.setAllowedMethods(List.of("GET", "POST", "PUT", "HEAD", "DELETE", "OPTIONS"));
    config.setAllowedOrigins(Collections.singletonList("http://localhost:5173"));
    config.setAllowCredentials(true);
    source.registerCorsConfiguration("/**", config);
    return source;
}
@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http, CorsConfigurationSource corsConfigurationSource) throws Exception {
    CookieCsrfTokenRepository cookieCsrfTokenRepository = CookieCsrfTokenRepository.withHttpOnlyFalse();
    CsrfTokenRequestAttributeHandler csrfTokenRequestAttributeHandler = new CsrfTokenRequestAttributeHandler();
    csrfTokenRequestAttributeHandler.setCsrfRequestAttributeName(null);
    http
            .authorizeHttpRequests(authorize ->
                    authorize
                            .anyRequest().authenticated()
            )
            .cors(cors -> cors.configurationSource(corsConfigurationSource))
            .csrf(csrf ->
                    csrf
                            .csrfTokenRepository(cookieCsrfTokenRepository)
                            .csrfTokenRequestHandler(csrfTokenRequestAttributeHandler))
            .exceptionHandling(exceptionHandling ->
                    exceptionHandling.authenticationEntryPoint(authenticationEntryPoint()))
            .oauth2Login(Customizer.withDefaults())
            .oauth2Client(Customizer.withDefaults());
    return http.build();
}

路由函数

@Bean
public RouterFunction<ServerResponse> gateweaySetResponseHeader(){
    return route("add_response_header").
            GET("/**", http("http://authserver:9000"))
            .after(addResponseHeader("Access-Control-Allow-Origin", "http://localhost:5173"))
            .build();
}

请求头

Cache-Control
    no-cache, no-store, max-age=0, must-revalidate
Connection
    keep-alive
Content-Length
    0
Date
    Thu, 27 Feb 2025 08:14:17 GMT
Expires
    0
Keep-Alive
    timeout=60
Location
    http://authserver:9000/login
Pragma
    no-cache
Set-Cookie
    JSESSIONID=B21263D037E86E9C34E195C8F6B521CF; Path=/; HttpOnly
X-Content-Type-Options
    nosniff
X-Frame-Options
    DENY
X-XSS-Protection
    0

响应头

Accept
    */*
Accept-Encoding
    gzip, deflate
Accept-Language
    ru-RU,ru;q=0.8,en-US;q=0.5,en;q=0.3
Connection
    keep-alive
Host
    authserver:9000
Origin
    null
Priority
    u=0
Referer
    http://localhost:5173/
User-Agent
    Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/136.0

内容的提问来源于stack exchange,提问作者Merkodanov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 04:25:16