You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Swagger-UI调用Salesforce API遭遇CORS跨域错误求助

Salesforce REST API + Swagger-UI CORS问题排查与解决

一、Swagger.json 问题检查

你的swagger.json语法无错误,但存在几个可优化细节(不影响CORS错误):

  • 拼写错误:"Creating new Accounr"应改为"Creating new Account"
  • 响应状态码缺失:POST接口仅定义405,建议补充201(创建成功)等状态码完善文档
  • schemes冗余:Salesforce API仅支持HTTPS,建议移除"http"避免混淆
  • 核心问题:CORS错误根源是浏览器直接请求Salesforce的token端点(https://login.salesforce.com/services/oauth2/token),该端点默认禁止前端跨域请求——你在Salesforce后台配置的CORS规则仅针对自定义Apex REST接口,不覆盖官方登录token接口。

二、CORS问题解决方案

方案1:后端代理转发Token请求

通过SpringBoot新增代理接口,让浏览器请求同域后端接口,再由后端转发到Salesforce token端点,绕过浏览器CORS限制:

  1. 新增代理控制器:
import org.springframework.http.HttpHeaders;
import org.springframework.http.HttpMethod;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestBody;
import org.springframework.web.bind.annotation.RestController;
import org.springframework.web.client.RestTemplate;

@RestController
public class SalesforceTokenProxy {

    private final RestTemplate restTemplate = new RestTemplate();

    @PostMapping("/proxy/salesforce/token")
    public ResponseEntity<String> forwardTokenRequest(@RequestBody String requestBody) {
        String salesforceTokenUrl = "https://login.salesforce.com/services/oauth2/token";
        HttpHeaders headers = new HttpHeaders();
        headers.set("Content-Type", "application/x-www-form-urlencoded");

        ResponseEntity<String> sfResponse = restTemplate.exchange(
                salesforceTokenUrl,
                HttpMethod.POST,
                new org.springframework.http.HttpEntity<>(requestBody, headers),
                String.class
        );

        return ResponseEntity.status(sfResponse.getStatusCode())
                .headers(sfResponse.getHeaders())
                .body(sfResponse.getBody());
    }
}
  1. 修改swagger.json中的tokenUrl为代理地址:
"securityDefinitions": {
    "salesforce_auth": {
        "type": "oauth2",
        "tokenUrl": "http://localhost:8080/proxy/salesforce/token",
        "flow": "password",
        "scopes": {
            "read:accounts": "read accounts",
            "write:accounts": "modify accounts"
        }
    }
}

方案2:配置Swagger-UI内置代理

利用Swagger-UI代理功能,通过后端转发请求:

  1. 配置SpringBoot资源处理器:
import org.springframework.context.annotation.Configuration;
import org.springframework.web.servlet.config.annotation.ResourceHandlerRegistry;
import org.springframework.web.servlet.config.annotation.WebMvcConfigurer;

@Configuration
public class SwaggerUiProxyConfig implements WebMvcConfigurer {

    @Override
    public void addResourceHandlers(ResourceHandlerRegistry registry) {
        // 配置Swagger-UI资源
        registry.addResourceHandler("/swagger-ui/**")
                .addResourceLocations("classpath:/META-INF/resources/webjars/springfox-swagger-ui/");
        // 配置代理转发Salesforce token请求
        registry.addResourceHandler("/proxy/**")
                .addResourceLocations("https://login.salesforce.com/")
                .setCachePeriod(0);
    }
}
  1. 修改swagger.json的tokenUrl为代理路径:
"tokenUrl": "/proxy/services/oauth2/token"

方案3:确认Salesforce Apex API的CORS配置(针对业务接口)

虽不解决token的CORS,但需确保自定义REST接口正常访问:

  • 进入Salesforce后台 Setup > Security > CORS
  • 添加允许的源:http://localhost:8080(不要加末尾斜杠)
  • 确认Apex REST类的@RestResource注解路径正确,且CORS规则包含该源

三、额外提示

  • SpringBoot 2.7.12与springfox 2.9.2兼容正常,但springfox已停止维护,建议后续迁移到springdoc-openapi
  • OAuth2的password flow在浏览器环境存在安全风险(暴露用户名密码),仅用于测试,生产环境建议使用authorization code flow

内容的提问来源于stack exchange,提问作者Ankit Fulzele

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 14:27:51