You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security 6.2.3(Spring Boot 3.2.4)CORS配置无效求助

Spring Security 6.2.3 + Spring Boot 3.2.4 跨域问题解决

我查过很多相关帖子,但要么失效要么版本过旧,均不适用于Spring Security 6.2.3与Spring Boot 3.2.4。为解决前端与Spring端点的跨域问题,我尝试了多种方案但均无效,以下是其中一种尝试过的配置:

安全配置类

@Bean
CorsConfigurationSource corsConfigurationSource() {
    CorsConfiguration configuration = new CorsConfiguration();
    configuration.setAllowedOrigins(Arrays.asList("http://localhost:5123"));
    configuration.setAllowedMethods(Arrays.asList("GET","POST","DELETE","OPTIONS"));
    UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
    source.registerCorsConfiguration("/**", configuration);
    return source;
}

@Bean
public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception {
    return httpSecurity
            .cors(cors -> cors.disable())
            .csrf(csrf -> csrf.disable())
            .authorizeHttpRequests(auth -> auth
                    .requestMatchers(
                            AntPathRequestMatcher.antMatcher("/api/v1/test")
                    )
                    .permitAll()
                    .requestMatchers("/api/**")
                    .authenticated()
            )
            .sessionManagement(sess -> sess.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
            .build();
}

测试用简单端点

@RestController
@RequestMapping(value = "/api/v1/")
@Slf4j
public class TestController {

    @GetMapping(value = "test", produces = "application/json")
    @Operation(method = "GET")
    public ResponseEntity<Test> getTest() {
       // 业务逻辑
    }
}

为何我的Angular前端仍持续出现如下错误?

Access to XMLHttpRequest at 'https://servername/api/v1/test' from origin 'http://localhost:5123' has been blocked by CORS policy: Response to preflight request doesn't pass access control check: No 'Access-Control-Allow-Origin' header is present on the requested resource.


问题根源

你在SecurityFilterChain中显式调用了.cors(cors -> cors.disable()),这直接禁用了Spring Security的CORS支持,导致你定义的CorsConfigurationSource Bean完全不生效,后端不会处理跨域请求的预检和响应头添加。

修复方案

1. 修改SecurityFilterChain配置

移除CORS禁用的代码,改为启用CORS并绑定自定义的配置源:

@Bean
public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception {
    return httpSecurity
            .cors(cors -> cors.configurationSource(corsConfigurationSource())) // 启用CORS并使用自定义配置
            .csrf(csrf -> csrf.disable())
            .authorizeHttpRequests(auth -> auth
                    .requestMatchers(AntPathRequestMatcher.antMatcher("/api/v1/test"))
                    .permitAll()
                    .requestMatchers("/api/**")
                    .authenticated()
            )
            .sessionManagement(sess -> sess.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
            .build();
}

2. 完善CORS配置(可选但推荐)

根据实际业务需求补充必要的跨域配置,比如允许自定义请求头、凭证传递:

@Bean
CorsConfigurationSource corsConfigurationSource() {
    CorsConfiguration configuration = new CorsConfiguration();
    configuration.setAllowedOrigins(Arrays.asList("http://localhost:5123"));
    configuration.setAllowedMethods(Arrays.asList("GET","POST","DELETE","OPTIONS"));
    configuration.setAllowedHeaders(Arrays.asList("*")); // 允许所有请求头,可根据实际场景缩小范围
    configuration.setAllowCredentials(true); // 若前端需要携带Cookie等凭证,开启此项
    UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
    source.registerCorsConfiguration("/**", configuration);
    return source;
}

额外注意点

  • 确保AllowedOrigins中的地址与前端完全一致,包括协议(http/https)、域名、端口
  • OPTIONS预检请求会被Spring Security的CORS过滤器自动处理,无需额外配置权限放行
  • 如果前端发送自定义请求头,需在AllowedHeaders中明确指定或使用*

内容的提问来源于stack exchange,提问作者Ciube

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 05:35:15