Spring Webflux代理Swagger POST请求失败的CORS问题咨询
我正将代理从Delphi迁移至Java Spring Webflux。通过Postman访问新代理的请求正常,但Swagger中的POST请求失败(旧代理可正常运行),报错:
Failed to fetch. Possible Reasons: CORS Network Failure URL scheme must be "http" or "https" for CORS request.
调试发现,最后到达服务器的是针对端点的OPTIONS请求,返回200状态码及若干响应头。通过Postman对比新旧代理的OPTIONS响应头,新代理包含旧代理的所有必要头(含Swagger预检所需头),还多了一些额外头。
更新:分析Swagger发出的OPTIONS请求,发现其带有Origin: https://editor-next.swagger.io头,该请求返回403 FORBIDDEN导致Swagger显示“Failed to Fetch”。在Postman中复现此问题,移除Origin头后返回200 OK。
添加CorsConfig配置后,Postman请求正常,但Swagger仍失败,报错:
Access to fetch at 'https://localhost:8080/endpoint' from origin 'https://editor-next.swagger.io' has been blocked by CORS policy: The 'Access-Control-Allow-Origin' header contains multiple values '*, *', but only one is allowed. Have the server send the header with a valid value, or, if an opaque response serves your needs, set the request's mode to 'no-cors' to fetch the resource with CORS disabled.
奇怪的是,Postman中相同请求的Access-Control-Allow-Origin头仅含一个"*",且Swagger显示失败但请求实际已执行并生效。移除corsConfig.addAllowedOrigin("*");会导致请求因缺少该头而失败。
咨询问题
为何Swagger中会出现Access-Control-Allow-Origin头重复的'*, *',如何解决?
内容的提问来源于stack exchange,提问作者Kira Resari

