You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot CORS withCredentials报错:Access-Control-Allow-Origin设为*不支持凭证

解决「Credential is not supported if the CORS header 'Access-Control-Allow-Origin' is '*'」错误

这个错误的核心逻辑很清晰:当请求携带凭证(如Cookie、HTTP认证信息)时,浏览器禁止Access-Control-Allow-Origin设为通配符*,必须返回与请求Origin完全匹配的具体值。

从你提供的代码来看,问题出在corsUrls的配置上:

  • 若corsUrls直接包含*,即便使用setAllowedOriginPatterns,在开启allowCredentials(true)的场景下,Spring仍可能在预检请求中返回*,触发浏览器的校验错误。
  • setAllowedOriginPatterns支持的是模式匹配规则(比如https://*.yourdomain.com),而非单纯的通配符*。

修复步骤

  1. 修正corsUrls配置
    确保corsUrls是具体的源列表或合法的匹配模式,示例如下:

    // 方式1:指定具体前端域名
    List<String> corsUrls = Arrays.asList("https://your-frontend-app.com", "https://admin.yourdomain.com");
    // 方式2:匹配同一主域下的所有子域名
    List<String> corsUrls = Arrays.asList("https://*.yourdomain.com");
    
  2. 调整后的完整过滤器代码

    @Bean
    public CorsFilter corsFilter() {
        List<String> allowedMethods = Arrays.asList("GET", "PUT", "DELETE", "PATCH", "POST", "HEAD", "OPTIONS");
        CorsConfiguration config = new CorsConfiguration();
        // 传入合法的源/模式列表
        config.setAllowedOriginPatterns(Arrays.asList("https://*.yourdomain.com", "https://your-frontend-app.com"));
        config.setAllowedMethods(allowedMethods);
        config.setAllowCredentials(true);
        config.addAllowedHeader(CorsConfiguration.ALL);
        // 可选:暴露前端需要读取的自定义响应头
        config.addExposedHeader("Authorization");
    
        UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
        source.registerCorsConfiguration("/**", config);
    
        return new CorsFilter(source);
    }
    
  3. 关键注意事项

    • 只要开启allowCredentials(true),就绝对不能使用单纯的*作为允许的源,无论调用setAllowedOrigins还是setAllowedOriginPatterns都不行。
    • 配置正确后,Spring的CorsFilter会自动处理预检请求(OPTIONS)和实际请求的Access-Control-Allow-Origin值,确保与请求的Origin完全匹配。

内容的提问来源于stack exchange,提问作者Ashish Bhosle

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 06:15:45