You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

React与SpringBoot应用全局CORS配置失效问题求助

问题描述

跨源请求被阻止:同源策略不允许读取http://localhost:8080/echo的远程资源。(原因:缺少CORS头‘Access-Control-Allow-Origin’)。状态码:403。

已配置SpringBoot全局CORS配置如下,但全局配置无效,仅方法级CORS配置可正常工作:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.servlet.config.annotation.CorsRegistry;
import org.springframework.web.servlet.config.annotation.WebMvcConfigurer;

@Configuration
public class CorsConfig {
    @Bean
    public WebMvcConfigurer corsConfigurer() {
        return new WebMvcConfigurer() {
            @Override
            public void addCorsMappings(CorsRegistry registry) {
                registry.addMapping("/**")
                    .allowedOrigins("http://localhost:3000")
                    .allowedMethods("*")
                    .allowedHeaders("*")
                    .allowCredentials(true);
            }
        };
    }
}

排查与解决方案

1. 确认配置类被Spring容器扫描

检查CorsConfig类所在包是否被@SpringBootApplication的scanBasePackages覆盖,或直接将配置类放在启动类的同级/子包下,确保Spring能加载该配置Bean。

2. 处理Spring Security拦截冲突

若项目集成了Spring Security,默认安全规则会在CORS过滤器前拦截请求,导致全局配置的CORS头无法生效。需在Security配置中单独启用CORS:

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
import org.springframework.web.cors.CorsConfiguration;
import org.springframework.web.cors.CorsConfigurationSource;
import org.springframework.web.cors.UrlBasedCorsConfigurationSource;
import java.util.Arrays;

@Configuration
@EnableWebSecurity
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.cors().and()
            .csrf().disable()
            .authorizeRequests()
            .anyRequest().permitAll();
    }

    @Bean
    CorsConfigurationSource corsConfigurationSource() {
        CorsConfiguration configuration = new CorsConfiguration();
        configuration.setAllowedOrigins(Arrays.asList("http://localhost:3000"));
        configuration.setAllowedMethods(Arrays.asList("GET", "POST", "PUT", "DELETE", "OPTIONS"));
        configuration.setAllowedHeaders(Arrays.asList("*"));
        configuration.setAllowCredentials(true);
        UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
        source.registerCorsConfiguration("/**", configuration);
        return source;
    }
}

3. 调整自定义过滤器执行顺序

若项目存在自定义过滤器,且其执行顺序早于Spring默认CORS过滤器,会导致请求被提前拦截。可通过设置高优先级确保CORS过滤器先执行:

import org.springframework.core.Ordered;
import org.springframework.core.annotation.Order;
import org.springframework.stereotype.Component;
import javax.servlet.*;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;

@Component
@Order(Ordered.HIGHEST_PRECEDENCE)
public class CorsFilter implements Filter {

    @Override
    public void doFilter(ServletRequest req, ServletResponse res, FilterChain chain) throws IOException, ServletException {
        HttpServletResponse response = (HttpServletResponse) res;
        response.setHeader("Access-Control-Allow-Origin", "http://localhost:3000");
        response.setHeader("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE, OPTIONS");
        response.setHeader("Access-Control-Allow-Headers", "*");
        response.setHeader("Access-Control-Allow-Credentials", "true");
        chain.doFilter(req, res);
    }

    @Override
    public void init(FilterConfig filterConfig) {}

    @Override
    public void destroy() {}
}

添加此过滤器后,可移除原WebMvcConfigurer方式的全局配置,避免冲突。

4. 验证Origin匹配性

确认React应用的访问地址确实是http://localhost:3000,无端口、协议(如http/https)错误。若需支持多个源,可通过Arrays.asList("http://localhost:3000", "http://xxx")扩展配置。

内容的提问来源于stack exchange,提问作者Adharsh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 16:55:19