SpringBoot配置CORS后GET请求仍遭跨域拦截问题求助
1. 先修复前端请求URL的异常
从错误信息里看到请求URL是p://localhost:8082/api/v1/user?email=l%40gmail.com,协议部分缺失了http://,这大概率是前端API的baseURL配置错误(比如漏写了协议头)。浏览器解析错误的URL会直接导致CORS校验逻辑异常,优先把前端的baseURL改成完整的http://localhost:8082/api/v1。
2. 处理Spring Security的拦截(如果项目用了Security)
如果你的SpringBoot项目集成了Spring Security,默认配置会拦截所有请求,包括CORS的预检OPTIONS请求,这时候你写的WebMvc全局CORS配置根本不会生效。需要在Security配置类里专门开启CORS支持:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.http.HttpMethod; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; import org.springframework.security.web.SecurityFilterChain; import org.springframework.web.cors.CorsConfiguration; import org.springframework.web.cors.CorsConfigurationSource; import org.springframework.web.cors.UrlBasedCorsConfigurationSource; import java.util.List; @Configuration @EnableWebSecurity public class SecurityConfig { @Bean public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { http // 启用自定义CORS配置 .cors(cors -> cors.configurationSource(corsConfigurationSource())) .csrf(csrf -> csrf.disable()) // 根据业务场景决定是否关闭CSRF .authorizeHttpRequests(auth -> auth // 允许OPTIONS预检请求直接通过 .requestMatchers(HttpMethod.OPTIONS, "/**").permitAll() // 其他接口权限配置按需添加 ); return http.build(); } @Bean public CorsConfigurationSource corsConfigurationSource() { CorsConfiguration config = new CorsConfiguration(); // 不能用*,因为请求带了认证头,必须指定具体前端地址 config.setAllowedOrigins(List.of("http://localhost:5173")); config.setAllowedMethods(List.of("GET", "POST", "PUT", "DELETE", "OPTIONS")); config.setAllowedHeaders(List.of("*")); // 允许携带认证信息(比如Authorization头) config.setAllowCredentials(true); // 暴露前端需要读取的响应头(可选,比如自定义token头) config.setExposedHeaders(List.of("Authorization")); UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource(); source.registerCorsConfiguration("/**", config); return source; } }
3. 修正全局CORS配置的Credentials兼容问题
你的请求带了认证头(getAuthHeader()),根据CORS规范:当请求包含credentials(比如Cookie、Authorization头)时,Access-Control-Allow-Origin不能设为*,必须指定具体的源,同时要开启allowCredentials。
修改原CorsConfig:
package com.sysmap.showus.services.utils.config; import org.springframework.context.annotation.Configuration; import org.springframework.web.servlet.config.annotation.CorsRegistry; import org.springframework.web.servlet.config.annotation.WebMvcConfigurer; @Configuration public class CorsConfig implements WebMvcConfigurer { @Override public void addCorsMappings(CorsRegistry registry) { registry.addMapping("/**") // 替换为你的前端实际地址,禁止用* .allowedOrigins("http://localhost:5173") .allowedMethods("*") .allowedHeaders("*") // 允许携带认证信息 .allowCredentials(true) // 暴露前端需要访问的响应头(可选) .exposedHeaders("Authorization"); } }
同时前端如果用Axios,需要开启withCredentials确保请求携带认证信息:
const api = axios.create({ baseURL: 'http://localhost:8082/api/v1', withCredentials: true });
4. 检查自定义过滤器的执行顺序
如果项目里有自定义过滤器,要确保它在CORS过滤器之后执行。有些过滤器会直接返回错误响应,跳过了CORS处理逻辑,导致响应头缺失。可以通过@Order注解调整顺序,CORS过滤器的默认顺序是Ordered.HIGHEST_PRECEDENCE + 10,自定义过滤器的顺序要低于这个值。
5. 验证预检请求的响应
打开浏览器开发者工具的网络标签,找到OPTIONS类型的预检请求,查看响应头是否包含Access-Control-Allow-Origin、Access-Control-Allow-Methods等CORS相关字段。如果预检请求的响应没有这些头,说明后端的CORS配置没生效,回到前面的步骤重新排查。
内容的提问来源于stack exchange,提问作者Luis Felipe Gongora Garcia

