Swagger-UI调用Salesforce API遭遇CORS跨域错误求助
Salesforce REST API + Swagger-UI CORS问题排查与解决
一、Swagger.json 问题检查
你的swagger.json语法无错误,但存在几个可优化细节(不影响CORS错误):
- 拼写错误:
"Creating new Accounr"应改为"Creating new Account" - 响应状态码缺失:POST接口仅定义405,建议补充201(创建成功)等状态码完善文档
- schemes冗余:Salesforce API仅支持HTTPS,建议移除
"http"避免混淆 - 核心问题:CORS错误根源是浏览器直接请求Salesforce的token端点(
https://login.salesforce.com/services/oauth2/token),该端点默认禁止前端跨域请求——你在Salesforce后台配置的CORS规则仅针对自定义Apex REST接口,不覆盖官方登录token接口。
二、CORS问题解决方案
方案1:后端代理转发Token请求
通过SpringBoot新增代理接口,让浏览器请求同域后端接口,再由后端转发到Salesforce token端点,绕过浏览器CORS限制:
- 新增代理控制器:
import org.springframework.http.HttpHeaders; import org.springframework.http.HttpMethod; import org.springframework.http.ResponseEntity; import org.springframework.web.bind.annotation.PostMapping; import org.springframework.web.bind.annotation.RequestBody; import org.springframework.web.bind.annotation.RestController; import org.springframework.web.client.RestTemplate; @RestController public class SalesforceTokenProxy { private final RestTemplate restTemplate = new RestTemplate(); @PostMapping("/proxy/salesforce/token") public ResponseEntity<String> forwardTokenRequest(@RequestBody String requestBody) { String salesforceTokenUrl = "https://login.salesforce.com/services/oauth2/token"; HttpHeaders headers = new HttpHeaders(); headers.set("Content-Type", "application/x-www-form-urlencoded"); ResponseEntity<String> sfResponse = restTemplate.exchange( salesforceTokenUrl, HttpMethod.POST, new org.springframework.http.HttpEntity<>(requestBody, headers), String.class ); return ResponseEntity.status(sfResponse.getStatusCode()) .headers(sfResponse.getHeaders()) .body(sfResponse.getBody()); } }
- 修改swagger.json中的tokenUrl为代理地址:
"securityDefinitions": { "salesforce_auth": { "type": "oauth2", "tokenUrl": "http://localhost:8080/proxy/salesforce/token", "flow": "password", "scopes": { "read:accounts": "read accounts", "write:accounts": "modify accounts" } } }
方案2:配置Swagger-UI内置代理
利用Swagger-UI代理功能,通过后端转发请求:
- 配置SpringBoot资源处理器:
import org.springframework.context.annotation.Configuration; import org.springframework.web.servlet.config.annotation.ResourceHandlerRegistry; import org.springframework.web.servlet.config.annotation.WebMvcConfigurer; @Configuration public class SwaggerUiProxyConfig implements WebMvcConfigurer { @Override public void addResourceHandlers(ResourceHandlerRegistry registry) { // 配置Swagger-UI资源 registry.addResourceHandler("/swagger-ui/**") .addResourceLocations("classpath:/META-INF/resources/webjars/springfox-swagger-ui/"); // 配置代理转发Salesforce token请求 registry.addResourceHandler("/proxy/**") .addResourceLocations("https://login.salesforce.com/") .setCachePeriod(0); } }
- 修改swagger.json的tokenUrl为代理路径:
"tokenUrl": "/proxy/services/oauth2/token"
方案3:确认Salesforce Apex API的CORS配置(针对业务接口)
虽不解决token的CORS,但需确保自定义REST接口正常访问:
- 进入Salesforce后台 Setup > Security > CORS
- 添加允许的源:
http://localhost:8080(不要加末尾斜杠) - 确认Apex REST类的
@RestResource注解路径正确,且CORS规则包含该源
三、额外提示
- SpringBoot 2.7.12与springfox 2.9.2兼容正常,但springfox已停止维护,建议后续迁移到springdoc-openapi
- OAuth2的password flow在浏览器环境存在安全风险(暴露用户名密码),仅用于测试,生产环境建议使用authorization code flow
内容的提问来源于stack exchange,提问作者Ankit Fulzele
相关产品推荐
相关产品推荐

