You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

JHipster6.3.0应用升级Spring Boot2.7.7后SpringFox的CSP异常求助

解决Springfox Swagger UI的CSP框架拦截问题

你的问题原因很明确:Swagger UI页面中嵌入了swagger.io的内容,但当前Content Security Policy(CSP)的frame-src指令仅允许加载自身('self')和data协议的资源,浏览器因此拦截了swagger.io的嵌入请求。

直接修改SecurityConfiguration中的CSP配置即可解决,在frame-src字段里添加https://swagger.io(推荐用HTTPS,避免混合内容风险):

.contentSecurityPolicy("default-src 'self'; frame-src 'self' data: https://swagger.io; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://storage.googleapis.com https://www.googletagmanager.com https://www.google-analytics.com; style-src 'self' https://fonts.googleapis.com 'unsafe-inline'; img-src 'self' www.googletagmanager.com https://www.google-analytics.com data:; font-src 'self' https://fonts.gstatic.com data:")

如果后续还有其他资源被CSP拦截,可根据浏览器控制台的错误提示,在对应的CSP指令中补充相应域名。

内容的提问来源于stack exchange,提问作者Amir Choubani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 02:06:27