升级Spring Boot 2.4.9后CORS配置allowCredentials=true报错如何解决
问题背景
将应用升级至Spring Boot 2.4.9版本时,程序抛出如下错误:
[10:07:07:487] [ERROR] - org.apache.juli.logging.DirectJDKLog.log(DirectJDKLog.java:175) - Servlet.service() for servlet [dispatcherServlet] in context with path [] threw exception java.lang.IllegalArgumentException: When allowCredentials is true, allowedOrigins cannot contain the special value "*" since that cannot be set on the "Access-Control-Allow-Origin" response header. To allow credentials to a set of origins, list them explicitly or consider using "allowedOriginPatterns" instead. at org.springframework.web.cors.CorsConfiguration.validateAllowCredentials(CorsConfiguration.java:473) ~[spring-web-5.3.9.jar!/:5.3.9] at org.springframework.web.cors.CorsConfiguration.checkOrigin(CorsConfiguration.java:577) ~[spring-web-5.3.9.jar!/:5.3.9] at org.springframework.web.cors.DefaultCorsProcessor.checkOrigin(DefaultCorsProcessor.java:174) ~[spring-web-5.3.9.jar!/:5.3.9] at org.springframework.web.cors.DefaultCorsProcessor.handleInternal(DefaultCorsProcessor.java:116) ~[spring-web-5.3.9.jar!/:5.3.9] at org.springframework.web.cors.DefaultCorsProcessor.processRequest(DefaultCorsProcessor.java:95) ~[spring-web-5.3.9.jar!/:5.3.9] at org.springframework.web.filter.CorsFilter.doFilterInternal(CorsFilter.java:87) ~[spring-web-5.3.9.jar!/:5.3.9] at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119) ~[spring-web-5.3.9.jar!/:5.3.9] at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:190) ~[tomcat-embed-core-9.0.50.jar!/:?] at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:163) ~[tomcat-embed-core-9.0.50.jar!/:?] at org.springframework.session.web.http.SessionRepositoryFilter.doFilterInternal(SessionRepositoryFilter.java:141) ~[spring-session-core-2.4.4.jar!/:2.4.4] at org.springframework.session.web.http.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:82) ~[spring-session-core-2.4.4.jar!/:2.4.4] at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:190) ~[tomcat-embed-core-9.0.50.jar!/:?] at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:163) ~[tomcat-embed-core-9.0.50.jar!/:?] at org.springframework.boot.actuate.metrics.web.servlet.WebMvcMetricsFilter.doFilterInternal(WebMvcMetricsFilter.java:97) ~[spring-boot-actuator-2.4.9.jar!/:2.4.9] at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119) ~[spring-web-5.3.9.jar!/:5.3.9] at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:190) ~[tomcat-embed-core-9.0.50.jar!/:?] at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:163) ~[tomcat-embed-core-9.0.50.jar!/:?] at org.springframework.web.filter.CharacterEncodingFilter.doFilterInternal(CharacterEncodingFilter.java:201) ~[spring-web-5.3.9.jar!/:5.3.9] at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119) ~[spring-web-5.3.9.jar!/:5.3.9] at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:190) ~[tomcat-embed-core-9.0.50.jar!/:?] at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:163) ~[tomcat-embed-core-9.0.50.jar!/:?]
错误触发原因
Spring Boot 2.4.9对应的Spring Web版本为5.3.9,该版本对CORS跨域配置校验逻辑做了严格收紧,完全对齐W3C的CORS规范要求:如果allowCredentials设置为true(允许跨域请求传递Cookie、Authorization头等凭证信息),则Access-Control-Allow-Origin响应头不能使用通配符*,否则浏览器会直接拦截该跨域请求。旧版本Spring Web未对该场景做强制校验,升级后触发校验逻辑直接抛出异常。
修复方案
可根据业务场景选择以下任意一种方案修复:
- 若业务不需要跨域传递凭证,直接将
allowCredentials设置为false,保留allowedOrigins = "*"的配置即可正常运行。 - 若需要传递凭证且允许的跨域源数量少、固定,可明确列出所有允许的源地址,例如:
allowedOrigins = Arrays.asList("https://www.example.com", "https://admin.example.com"),无需使用通配符。 - 若需要传递凭证且存在多域名匹配需求,将原
allowedOrigins的配置替换为allowedOriginPatterns,支持灵活的通配匹配规则,例如:allowedOriginPatterns = Arrays.asList("https://*.example.com")。
常见疑问解答
allowedOrigins配置*的优缺点
- 优点:配置成本极低,无需维护允许的跨域源列表,仅适合本地开发、测试阶段快速调试功能使用。
- 缺点:
- 安全风险极高,相当于放开所有站点的跨域访问权限,恶意站点可直接发起跨域请求窃取用户敏感数据,生产环境使用会直接导致CSRF等安全漏洞。
- 不符合CORS规范对带凭证请求的限制,Spring Web 5.3+版本会直接抛出异常,无法正常运行。
为什么需要指定allowedOriginPatterns
allowedOriginPatterns是Spring Web 5.3+版本新增的配置项,用于解决allowedOrigins无法同时支持通配匹配和带凭证跨域的问题:
allowedOrigins的通配符*是全匹配,响应头会直接返回Access-Control-Allow-Origin: *,不符合带凭证场景的CORS规范;而allowedOriginPatterns支持前缀、后缀、多级路径等灵活匹配规则,匹配到请求源后会在响应头返回实际请求的源地址,而非通配符,完全符合规范要求,可与allowCredentials = true同时使用。- 相比完全放开的
*配置,allowedOriginPatterns可以限定匹配的域名范围,在满足多域名跨域需求的同时降低安全风险。
内容的提问来源于stack exchange,提问作者Dolphin
相关产品推荐
相关产品推荐

