Spring Cloud Function是否支持类似Spring Security Filter Chains的过滤链功能?
Spring Cloud Function AWS环境CORS非侵入实现方案
核心问题答复
3.1.3版本的Spring Cloud Function没有内置类似Spring Security Filter Chain的全局拦截链原生组件,你提到的Servlet环境CorsFilter方案在标准AWS Lambda函数runtime下无法生效,因为该场景没有启动Servlet容器,不支持Servlet Filter规范。3.2及以上版本新增了更完善的函数全局拦截扩展,但3.1.3版本可通过下方方案实现需求。
非侵入式CORS实现方案(不修改业务逻辑)
推荐使用Spring Cloud Function提供的FunctionCustomizer扩展机制,全局包装所有函数实例,统一处理响应头,代码示例如下:
import org.springframework.cloud.function.context.FunctionCustomizer; import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import com.amazonaws.services.lambda.runtime.events.APIGatewayProxyRequestEvent; import com.amazonaws.services.lambda.runtime.events.APIGatewayProxyResponseEvent; import java.util.HashMap; import java.util.Map; @Configuration public class CorsConfig { @Bean public FunctionCustomizer<?, ?> corsFunctionCustomizer() { return (function, functionRegistration) -> { // 仅适配处理API Gateway代理请求的函数 if (function.getInputType().getRawClass().equals(APIGatewayProxyRequestEvent.class) && function.getOutputType().getRawClass().equals(APIGatewayProxyResponseEvent.class)) { return input -> { APIGatewayProxyRequestEvent request = (APIGatewayProxyRequestEvent) input; APIGatewayProxyResponseEvent response = (APIGatewayProxyResponseEvent) function.apply(input); // 统一注入CORS头 Map<String, String> headers = response.getHeaders() != null ? response.getHeaders() : new HashMap<>(); headers.put("Access-Control-Allow-Origin", "*"); headers.put("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE, OPTIONS"); headers.put("Access-Control-Allow-Headers", "Content-Type, Authorization"); response.setHeaders(headers); // 直接处理OPTIONS预检请求无需进入业务逻辑 if ("OPTIONS".equals(request.getHttpMethod())) { response.setStatusCode(204); } return response; }; } return function; }; } }
该方案属于集成层配置,完全不侵入业务函数代码,全局生效,兼容3.1.3版本所有特性。
补充说明
如果不需要处理自定义CORS逻辑,也可以直接在AWS API Gateway控制台配置CORS规则,网关会自动响应OPTIONS请求并注入响应头,无需修改任何函数代码。
内容的提问来源于stack exchange,提问作者Boris Fox
相关产品推荐
相关产品推荐

