You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot中设置Referrer-Policy为same-origin未生效如何解决?

解决Spring Boot中Referrer-Policy设置为same-origin的问题

你当前的配置仅针对X-Frame-Options设置了same-origin,并未显式配置Referrer-Policy,因此Spring Security会使用默认值no-referrer。要修改该行为,只需在headers配置块中添加Referrer-Policy的显式设置:

修改后的完整配置类如下:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.security.web.header.writers.referrer.ReferrerPolicy;

@Configuration
@EnableWebSecurity
public class SecurityConfiguration {
    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http.headers(headers -> headers
                .frameOptions(frameOptions -> frameOptions.sameOrigin())
                .referrerPolicy(referrer -> referrer.policy(ReferrerPolicy.SAME_ORIGIN))
        );
        return http.build();
    }
}

关键说明

  • 添加@Configuration和@EnableWebSecurity注解,确保Spring Security识别并加载该配置类(若你的类之前未添加)。
  • 在headers配置中通过referrerPolicy()方法指定ReferrerPolicy.SAME_ORIGIN,覆盖默认的no-referrer策略。

配置完成后重启应用,再次通过Wireshark或浏览器开发者工具的网络面板检查响应头,即可看到Referrer-Policy: same-origin已生效。

内容的提问来源于stack exchange,提问作者Pascal Jakobi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 11:35:57