You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Webflux代理Swagger POST请求失败的CORS问题咨询

Spring Webflux代理Swagger请求CORS头重复问题

我正将代理从Delphi迁移至Java Spring Webflux。通过Postman访问新代理的请求正常,但Swagger中的POST请求失败(旧代理可正常运行),报错:

Failed to fetch.
Possible Reasons:

CORS
Network Failure
URL scheme must be "http" or "https" for CORS request.

调试发现,最后到达服务器的是针对端点的OPTIONS请求,返回200状态码及若干响应头。通过Postman对比新旧代理的OPTIONS响应头,新代理包含旧代理的所有必要头(含Swagger预检所需头),还多了一些额外头。

更新:分析Swagger发出的OPTIONS请求,发现其带有Origin: https://editor-next.swagger.io头,该请求返回403 FORBIDDEN导致Swagger显示“Failed to Fetch”。在Postman中复现此问题,移除Origin头后返回200 OK。

添加CorsConfig配置后,Postman请求正常,但Swagger仍失败,报错:

Access to fetch at 'https://localhost:8080/endpoint' from origin 'https://editor-next.swagger.io' has been blocked by CORS policy: The 'Access-Control-Allow-Origin' header contains multiple values '*, *', but only one is allowed. Have the server send the header with a valid value, or, if an opaque response serves your needs, set the request's mode to 'no-cors' to fetch the resource with CORS disabled.

奇怪的是,Postman中相同请求的Access-Control-Allow-Origin头仅含一个"*",且Swagger显示失败但请求实际已执行并生效。移除corsConfig.addAllowedOrigin("*");会导致请求因缺少该头而失败。

咨询问题

为何Swagger中会出现Access-Control-Allow-Origin头重复的'*, *',如何解决?


内容的提问来源于stack exchange,提问作者Kira Resari

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 07:52:38