You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot 2.7.6+Spring Security下CORS禁用失败问题求助

Spring Boot CORS配置错误排查与修正

问题场景

基于Spring Boot 2.7.6的REST应用部署在https.dummy.cs,已集成Spring Security保护端点。部署在http://localhost:4200的Angular应用请求https://dev.dummy.cs时,浏览器触发CORS拦截:

Access to XMLHttpRequest at https.dummy.cs from origin http://locahost has been blocked by cors policy

尝试以下两种配置后问题仍未解决,现排查配置中的错误:

配置1:SecurityFilterChain

@Bean
public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception {
    //@formatter:off
    httpSecurity
            .httpBasic().disable()
            .csrf().disable().exceptionHandling().authenticationEntryPoint(sHandler);


    httpSecurity.cors().disable().
            
            antMatchers(ATT_WHITELIST).permitAll().
            anyRequest().authenticated();// whitelist Swagger UI resources
    

  ..
    httpSecurity.sessionManagement()
            .sessionCreationPolicy(SessionCreationPolicy.STATELESS);
    return httpSecurity.build();
}

配置2:CorsConfigurationSource

@Bean
public CorsConfigurationSource corsConfigurationSource() {
    UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
    CorsConfiguration config = new CorsConfiguration();
    config.setAllowedOrigins("dev.dummy.cs,https://dev.dummy.cs");
    config.setAllowedMethods(Arrays.asList("GET", "POST", "DELETE", "PUT"));
    config.addAllowedHeader("*");
    config.setAllowCredentials(true);
    source.registerCorsConfiguration("/**", config);
    return source;
}

配置错误分析

  1. SecurityFilterChain核心问题
    配置中调用了.cors().disable(),直接禁用了Spring Security的CORS支持,导致自定义的CorsConfigurationSource Bean完全不生效,这是问题根源。

  2. CorsConfigurationSource多处错误

    • setAllowedOrigins传入的是逗号分隔的单个字符串,但该方法要求传入字符串列表,这会导致仅生效一个无效的origin:"dev.dummy.cs,https://dev.dummy.cs";
    • 前端实际请求的origin是http://localhost:4200,但配置中未添加该origin,这是浏览器拦截请求的直接原因;
    • 错误信息中的http://locahost是拼写错误,实际前端origin是带端口的http://localhost:4200,CORS验证要求origin精确匹配(含协议、域名、端口)。

修正后的配置

修正SecurityFilterChain

移除.cors().disable(),启用CORS并关联自定义配置:

@Bean
public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception {
    //@formatter:off
    httpSecurity
            .httpBasic().disable()
            .csrf().disable()
            .exceptionHandling().authenticationEntryPoint(sHandler)
            .and()
            .cors() // 启用CORS,自动关联CorsConfigurationSource Bean
            .and()
            .authorizeHttpRequests() // Spring Boot 2.7+推荐写法
            .antMatchers(ATT_WHITELIST).permitAll()
            .anyRequest().authenticated()
            .and()
            .sessionManagement()
            .sessionCreationPolicy(SessionCreationPolicy.STATELESS);
    return httpSecurity.build();
}

修正CorsConfigurationSource

修正origin配置,添加前端实际的origin:

@Bean
public CorsConfigurationSource corsConfigurationSource() {
    UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
    CorsConfiguration config = new CorsConfiguration();
    // 精确添加允许的origin,生产环境避免使用*
    config.setAllowedOrigins(Arrays.asList("http://localhost:4200", "https://dev.dummy.cs"));
    config.setAllowedMethods(Arrays.asList("GET", "POST", "DELETE", "PUT"));
    config.addAllowedHeader("*");
    config.setAllowCredentials(true);
    // 若前端需要读取自定义响应头,需添加此处(比如Authorization)
    config.addExposedHeader("Authorization");
    source.registerCorsConfiguration("/**", config);
    return source;
}

额外注意事项

  • 确保前端请求的目标地址是https://dev.dummy.cs,与配置中的origin一致;
  • 生产环境中不要使用*作为allowedOrigins,必须精确指定信任的域名,避免安全风险;
  • Spring Boot 2.7及以上版本,推荐使用authorizeHttpRequests()替代旧的链式antMatchers写法,保证配置兼容性。

内容的提问来源于stack exchange,提问作者user1999453

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 04:40:38