You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

升级Spring Boot 2.4.9后CORS配置allowCredentials=true报错如何解决

问题背景

将应用升级至Spring Boot 2.4.9版本时,程序抛出如下错误:

[10:07:07:487] [ERROR] - org.apache.juli.logging.DirectJDKLog.log(DirectJDKLog.java:175) - Servlet.service() for servlet [dispatcherServlet] in context with path [] threw exception
java.lang.IllegalArgumentException: When allowCredentials is true, allowedOrigins cannot contain the special value "*" since that cannot be set on the "Access-Control-Allow-Origin" response header. To allow credentials to a set of origins, list them explicitly or consider using "allowedOriginPatterns" instead.
    at org.springframework.web.cors.CorsConfiguration.validateAllowCredentials(CorsConfiguration.java:473) ~[spring-web-5.3.9.jar!/:5.3.9]
    at org.springframework.web.cors.CorsConfiguration.checkOrigin(CorsConfiguration.java:577) ~[spring-web-5.3.9.jar!/:5.3.9]
    at org.springframework.web.cors.DefaultCorsProcessor.checkOrigin(DefaultCorsProcessor.java:174) ~[spring-web-5.3.9.jar!/:5.3.9]
    at org.springframework.web.cors.DefaultCorsProcessor.handleInternal(DefaultCorsProcessor.java:116) ~[spring-web-5.3.9.jar!/:5.3.9]
    at org.springframework.web.cors.DefaultCorsProcessor.processRequest(DefaultCorsProcessor.java:95) ~[spring-web-5.3.9.jar!/:5.3.9]
    at org.springframework.web.filter.CorsFilter.doFilterInternal(CorsFilter.java:87) ~[spring-web-5.3.9.jar!/:5.3.9]
    at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119) ~[spring-web-5.3.9.jar!/:5.3.9]
    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:190) ~[tomcat-embed-core-9.0.50.jar!/:?]
    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:163) ~[tomcat-embed-core-9.0.50.jar!/:?]
    at org.springframework.session.web.http.SessionRepositoryFilter.doFilterInternal(SessionRepositoryFilter.java:141) ~[spring-session-core-2.4.4.jar!/:2.4.4]
    at org.springframework.session.web.http.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:82) ~[spring-session-core-2.4.4.jar!/:2.4.4]
    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:190) ~[tomcat-embed-core-9.0.50.jar!/:?]
    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:163) ~[tomcat-embed-core-9.0.50.jar!/:?]
    at org.springframework.boot.actuate.metrics.web.servlet.WebMvcMetricsFilter.doFilterInternal(WebMvcMetricsFilter.java:97) ~[spring-boot-actuator-2.4.9.jar!/:2.4.9]
    at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119) ~[spring-web-5.3.9.jar!/:5.3.9]
    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:190) ~[tomcat-embed-core-9.0.50.jar!/:?]
    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:163) ~[tomcat-embed-core-9.0.50.jar!/:?]
    at org.springframework.web.filter.CharacterEncodingFilter.doFilterInternal(CharacterEncodingFilter.java:201) ~[spring-web-5.3.9.jar!/:5.3.9]
    at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:119) ~[spring-web-5.3.9.jar!/:5.3.9]
    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:190) ~[tomcat-embed-core-9.0.50.jar!/:?]
    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:163) ~[tomcat-embed-core-9.0.50.jar!/:?]
错误触发原因

Spring Boot 2.4.9对应的Spring Web版本为5.3.9,该版本对CORS跨域配置校验逻辑做了严格收紧,完全对齐W3C的CORS规范要求:如果allowCredentials设置为true(允许跨域请求传递Cookie、Authorization头等凭证信息),则Access-Control-Allow-Origin响应头不能使用通配符*,否则浏览器会直接拦截该跨域请求。旧版本Spring Web未对该场景做强制校验,升级后触发校验逻辑直接抛出异常。

修复方案

可根据业务场景选择以下任意一种方案修复:

  • 若业务不需要跨域传递凭证,直接将allowCredentials设置为false,保留allowedOrigins = "*"的配置即可正常运行。
  • 若需要传递凭证且允许的跨域源数量少、固定,可明确列出所有允许的源地址,例如:allowedOrigins = Arrays.asList("https://www.example.com", "https://admin.example.com"),无需使用通配符。
  • 若需要传递凭证且存在多域名匹配需求,将原allowedOrigins的配置替换为allowedOriginPatterns,支持灵活的通配匹配规则,例如:allowedOriginPatterns = Arrays.asList("https://*.example.com")。
常见疑问解答

allowedOrigins配置*的优缺点

  • 优点:配置成本极低,无需维护允许的跨域源列表,仅适合本地开发、测试阶段快速调试功能使用。
  • 缺点:
    • 安全风险极高,相当于放开所有站点的跨域访问权限,恶意站点可直接发起跨域请求窃取用户敏感数据,生产环境使用会直接导致CSRF等安全漏洞。
    • 不符合CORS规范对带凭证请求的限制,Spring Web 5.3+版本会直接抛出异常,无法正常运行。

为什么需要指定allowedOriginPatterns

allowedOriginPatterns是Spring Web 5.3+版本新增的配置项,用于解决allowedOrigins无法同时支持通配匹配和带凭证跨域的问题:

  • allowedOrigins的通配符*是全匹配,响应头会直接返回Access-Control-Allow-Origin: *,不符合带凭证场景的CORS规范;而allowedOriginPatterns支持前缀、后缀、多级路径等灵活匹配规则,匹配到请求源后会在响应头返回实际请求的源地址,而非通配符,完全符合规范要求,可与allowCredentials = true同时使用。
  • 相比完全放开的*配置,allowedOriginPatterns可以限定匹配的域名范围,在满足多域名跨域需求的同时降低安全风险。

内容的提问来源于stack exchange,提问作者Dolphin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.25 03:06:03