Spring Boot 2.7.6+Spring Security下CORS禁用失败问题求助
Spring Boot CORS配置错误排查与修正
问题场景
基于Spring Boot 2.7.6的REST应用部署在https.dummy.cs,已集成Spring Security保护端点。部署在http://localhost:4200的Angular应用请求https://dev.dummy.cs时,浏览器触发CORS拦截:
Access to XMLHttpRequest at https.dummy.cs from origin http://locahost has been blocked by cors policy
尝试以下两种配置后问题仍未解决,现排查配置中的错误:
配置1:SecurityFilterChain
@Bean public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception { //@formatter:off httpSecurity .httpBasic().disable() .csrf().disable().exceptionHandling().authenticationEntryPoint(sHandler); httpSecurity.cors().disable(). antMatchers(ATT_WHITELIST).permitAll(). anyRequest().authenticated();// whitelist Swagger UI resources .. httpSecurity.sessionManagement() .sessionCreationPolicy(SessionCreationPolicy.STATELESS); return httpSecurity.build(); }
配置2:CorsConfigurationSource
@Bean public CorsConfigurationSource corsConfigurationSource() { UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource(); CorsConfiguration config = new CorsConfiguration(); config.setAllowedOrigins("dev.dummy.cs,https://dev.dummy.cs"); config.setAllowedMethods(Arrays.asList("GET", "POST", "DELETE", "PUT")); config.addAllowedHeader("*"); config.setAllowCredentials(true); source.registerCorsConfiguration("/**", config); return source; }
配置错误分析
SecurityFilterChain核心问题
配置中调用了.cors().disable(),直接禁用了Spring Security的CORS支持,导致自定义的CorsConfigurationSourceBean完全不生效,这是问题根源。CorsConfigurationSource多处错误
setAllowedOrigins传入的是逗号分隔的单个字符串,但该方法要求传入字符串列表,这会导致仅生效一个无效的origin:"dev.dummy.cs,https://dev.dummy.cs";- 前端实际请求的origin是
http://localhost:4200,但配置中未添加该origin,这是浏览器拦截请求的直接原因; - 错误信息中的
http://locahost是拼写错误,实际前端origin是带端口的http://localhost:4200,CORS验证要求origin精确匹配(含协议、域名、端口)。
修正后的配置
修正SecurityFilterChain
移除.cors().disable(),启用CORS并关联自定义配置:
@Bean public SecurityFilterChain filterChain(HttpSecurity httpSecurity) throws Exception { //@formatter:off httpSecurity .httpBasic().disable() .csrf().disable() .exceptionHandling().authenticationEntryPoint(sHandler) .and() .cors() // 启用CORS,自动关联CorsConfigurationSource Bean .and() .authorizeHttpRequests() // Spring Boot 2.7+推荐写法 .antMatchers(ATT_WHITELIST).permitAll() .anyRequest().authenticated() .and() .sessionManagement() .sessionCreationPolicy(SessionCreationPolicy.STATELESS); return httpSecurity.build(); }
修正CorsConfigurationSource
修正origin配置,添加前端实际的origin:
@Bean public CorsConfigurationSource corsConfigurationSource() { UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource(); CorsConfiguration config = new CorsConfiguration(); // 精确添加允许的origin,生产环境避免使用* config.setAllowedOrigins(Arrays.asList("http://localhost:4200", "https://dev.dummy.cs")); config.setAllowedMethods(Arrays.asList("GET", "POST", "DELETE", "PUT")); config.addAllowedHeader("*"); config.setAllowCredentials(true); // 若前端需要读取自定义响应头,需添加此处(比如Authorization) config.addExposedHeader("Authorization"); source.registerCorsConfiguration("/**", config); return source; }
额外注意事项
- 确保前端请求的目标地址是
https://dev.dummy.cs,与配置中的origin一致; - 生产环境中不要使用
*作为allowedOrigins,必须精确指定信任的域名,避免安全风险; - Spring Boot 2.7及以上版本,推荐使用
authorizeHttpRequests()替代旧的链式antMatchers写法,保证配置兼容性。
内容的提问来源于stack exchange,提问作者user1999453
相关产品推荐
相关产品推荐

