You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot+Spring Security部署后CORS凭证头配置异常排查

解决Spring Boot+Spring Security跨域CORS错误(OpenShift部署场景)

问题根源

你的场景中,Spring Security的请求拦截优先级高于Spring MVC的CORS配置,导致MvcConfig里的规则未被正确应用;另外当开启allowCredentials(true)时,allowedOrigins使用*违反CORS规范,浏览器会拒绝识别Access-Control-Allow-Credentials头,最终触发报错。

解决方案

方案1:在Spring Security中启用CORS,复用MvcConfig规则

创建Spring Security配置类,明确启用CORS支持,自动关联你已有的MvcConfig配置(注意必须修改allowedOrigins为前端实际地址,不能用*):

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .cors() // 启用CORS,自动关联WebMvcConfigurer中的配置
            .and()
            .csrf().disable() // 根据业务需求决定是否禁用CSRF
            .authorizeRequests()
            .anyRequest().permitAll(); // 替换为你的实际权限规则
    }
}

同时修改配置文件中的cors.allowed-origins:

cors.allowed-origins=https://frontend.apps.ocpa.company.com

方案2:直接在Spring Security中配置CORS(独立配置)

如果不想依赖MvcConfig,可以直接在Security配置中定义CORS规则:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
import org.springframework.web.cors.CorsConfiguration;
import org.springframework.web.cors.CorsConfigurationSource;
import org.springframework.web.cors.UrlBasedCorsConfigurationSource;

import java.util.List;

@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .cors().configurationSource(corsConfigurationSource())
            .and()
            .csrf().disable()
            .authorizeRequests()
            .anyRequest().permitAll();
    }

    @Bean
    CorsConfigurationSource corsConfigurationSource() {
        CorsConfiguration config = new CorsConfiguration();
        // 明确指定允许的前端Origin,不能用*
        config.setAllowedOrigins(List.of("https://frontend.apps.ocpa.company.com"));
        // 允许的请求方法
        config.setAllowedMethods(List.of("GET", "POST", "PUT", "DELETE", "OPTIONS"));
        // 允许的请求头
        config.setAllowedHeaders(List.of("*"));
        // 开启凭证支持
        config.setAllowCredentials(true);

        UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
        source.registerCorsConfiguration("/**", config);
        return source;
    }
}

额外检查点

  1. 前端请求配置:确保Angular请求时开启withCredentials:
import { HttpClient } from '@angular/common/http';

// 在请求中添加withCredentials选项
this.http.get('https://backend.apps.ocpa.company.com/app/user/config', { withCredentials: true })
  .subscribe(response => {
    // 处理响应
  });
  1. OpenShift路由检查:确认后端路由未修改或移除CORS相关响应头,避免路由层过滤掉Access-Control-Allow-Credentials等关键头。

内容的提问来源于stack exchange,提问作者akarahman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 18:13:15