Spring Boot中设置Referrer-Policy为same-origin未生效如何解决?
解决Spring Boot中Referrer-Policy设置为same-origin的问题
你当前的配置仅针对X-Frame-Options设置了same-origin,并未显式配置Referrer-Policy,因此Spring Security会使用默认值no-referrer。要修改该行为,只需在headers配置块中添加Referrer-Policy的显式设置:
修改后的完整配置类如下:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.web.SecurityFilterChain; import org.springframework.security.web.header.writers.referrer.ReferrerPolicy; @Configuration @EnableWebSecurity public class SecurityConfiguration { @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http.headers(headers -> headers .frameOptions(frameOptions -> frameOptions.sameOrigin()) .referrerPolicy(referrer -> referrer.policy(ReferrerPolicy.SAME_ORIGIN)) ); return http.build(); } }
关键说明
- 添加
@Configuration和@EnableWebSecurity注解,确保Spring Security识别并加载该配置类(若你的类之前未添加)。 - 在
headers配置中通过referrerPolicy()方法指定ReferrerPolicy.SAME_ORIGIN,覆盖默认的no-referrer策略。
配置完成后重启应用,再次通过Wireshark或浏览器开发者工具的网络面板检查响应头,即可看到Referrer-Policy: same-origin已生效。
内容的提问来源于stack exchange,提问作者Pascal Jakobi
相关产品推荐
相关产品推荐

