Spring Security 6.2.3(Spring Boot 3.2.4)CORS配置无效求助
Spring Security 6.2.3 + Spring Boot 3.2.4 跨域问题解决
我查过很多相关帖子,但要么失效要么版本过旧,均不适用于Spring Security 6.2.3与Spring Boot 3.2.4。为解决前端与Spring端点的跨域问题,我尝试了多种方案但均无效,以下是其中一种尝试过的配置:
安全配置类
@Bean CorsConfigurationSource corsConfigurationSource() { CorsConfiguration configuration = new CorsConfiguration(); configuration.setAllowedOrigins(Arrays.asList("http://localhost:5123")); configuration.setAllowedMethods(Arrays.asList("GET","POST","DELETE","OPTIONS")); UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource(); source.registerCorsConfiguration("/**", configuration); return source; } @Bean public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception { return httpSecurity .cors(cors -> cors.disable()) .csrf(csrf -> csrf.disable()) .authorizeHttpRequests(auth -> auth .requestMatchers( AntPathRequestMatcher.antMatcher("/api/v1/test") ) .permitAll() .requestMatchers("/api/**") .authenticated() ) .sessionManagement(sess -> sess.sessionCreationPolicy(SessionCreationPolicy.STATELESS)) .build(); }
测试用简单端点
@RestController @RequestMapping(value = "/api/v1/") @Slf4j public class TestController { @GetMapping(value = "test", produces = "application/json") @Operation(method = "GET") public ResponseEntity<Test> getTest() { // 业务逻辑 } }
为何我的Angular前端仍持续出现如下错误?
Access to XMLHttpRequest at 'https://servername/api/v1/test' from origin 'http://localhost:5123' has been blocked by CORS policy: Response to preflight request doesn't pass access control check: No 'Access-Control-Allow-Origin' header is present on the requested resource.
问题根源
你在SecurityFilterChain中显式调用了.cors(cors -> cors.disable()),这直接禁用了Spring Security的CORS支持,导致你定义的CorsConfigurationSource Bean完全不生效,后端不会处理跨域请求的预检和响应头添加。
修复方案
1. 修改SecurityFilterChain配置
移除CORS禁用的代码,改为启用CORS并绑定自定义的配置源:
@Bean public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception { return httpSecurity .cors(cors -> cors.configurationSource(corsConfigurationSource())) // 启用CORS并使用自定义配置 .csrf(csrf -> csrf.disable()) .authorizeHttpRequests(auth -> auth .requestMatchers(AntPathRequestMatcher.antMatcher("/api/v1/test")) .permitAll() .requestMatchers("/api/**") .authenticated() ) .sessionManagement(sess -> sess.sessionCreationPolicy(SessionCreationPolicy.STATELESS)) .build(); }
2. 完善CORS配置(可选但推荐)
根据实际业务需求补充必要的跨域配置,比如允许自定义请求头、凭证传递:
@Bean CorsConfigurationSource corsConfigurationSource() { CorsConfiguration configuration = new CorsConfiguration(); configuration.setAllowedOrigins(Arrays.asList("http://localhost:5123")); configuration.setAllowedMethods(Arrays.asList("GET","POST","DELETE","OPTIONS")); configuration.setAllowedHeaders(Arrays.asList("*")); // 允许所有请求头,可根据实际场景缩小范围 configuration.setAllowCredentials(true); // 若前端需要携带Cookie等凭证,开启此项 UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource(); source.registerCorsConfiguration("/**", configuration); return source; }
额外注意点
- 确保
AllowedOrigins中的地址与前端完全一致,包括协议(http/https)、域名、端口 - OPTIONS预检请求会被Spring Security的CORS过滤器自动处理,无需额外配置权限放行
- 如果前端发送自定义请求头,需在
AllowedHeaders中明确指定或使用*
内容的提问来源于stack exchange,提问作者Ciube
相关产品推荐
相关产品推荐

