Spring Boot+Spring Security部署后CORS凭证头配置异常排查
解决Spring Boot+Spring Security跨域CORS错误(OpenShift部署场景)
问题根源
你的场景中,Spring Security的请求拦截优先级高于Spring MVC的CORS配置,导致MvcConfig里的规则未被正确应用;另外当开启allowCredentials(true)时,allowedOrigins使用*违反CORS规范,浏览器会拒绝识别Access-Control-Allow-Credentials头,最终触发报错。
解决方案
方案1:在Spring Security中启用CORS,复用MvcConfig规则
创建Spring Security配置类,明确启用CORS支持,自动关联你已有的MvcConfig配置(注意必须修改allowedOrigins为前端实际地址,不能用*):
import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; @Configuration @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http .cors() // 启用CORS,自动关联WebMvcConfigurer中的配置 .and() .csrf().disable() // 根据业务需求决定是否禁用CSRF .authorizeRequests() .anyRequest().permitAll(); // 替换为你的实际权限规则 } }
同时修改配置文件中的cors.allowed-origins:
cors.allowed-origins=https://frontend.apps.ocpa.company.com
方案2:直接在Spring Security中配置CORS(独立配置)
如果不想依赖MvcConfig,可以直接在Security配置中定义CORS规则:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; import org.springframework.web.cors.CorsConfiguration; import org.springframework.web.cors.CorsConfigurationSource; import org.springframework.web.cors.UrlBasedCorsConfigurationSource; import java.util.List; @Configuration @EnableWebSecurity public class SecurityConfig extends WebSecurityConfigurerAdapter { @Override protected void configure(HttpSecurity http) throws Exception { http .cors().configurationSource(corsConfigurationSource()) .and() .csrf().disable() .authorizeRequests() .anyRequest().permitAll(); } @Bean CorsConfigurationSource corsConfigurationSource() { CorsConfiguration config = new CorsConfiguration(); // 明确指定允许的前端Origin,不能用* config.setAllowedOrigins(List.of("https://frontend.apps.ocpa.company.com")); // 允许的请求方法 config.setAllowedMethods(List.of("GET", "POST", "PUT", "DELETE", "OPTIONS")); // 允许的请求头 config.setAllowedHeaders(List.of("*")); // 开启凭证支持 config.setAllowCredentials(true); UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource(); source.registerCorsConfiguration("/**", config); return source; } }
额外检查点
- 前端请求配置:确保Angular请求时开启
withCredentials:
import { HttpClient } from '@angular/common/http'; // 在请求中添加withCredentials选项 this.http.get('https://backend.apps.ocpa.company.com/app/user/config', { withCredentials: true }) .subscribe(response => { // 处理响应 });
- OpenShift路由检查:确认后端路由未修改或移除CORS相关响应头,避免路由层过滤掉
Access-Control-Allow-Credentials等关键头。
内容的提问来源于stack exchange,提问作者akarahman
相关产品推荐
相关产品推荐

