You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在SonarQube中启用CORS?解决Angular4跨域认证405问题

解决SonarQube加Basic Auth后Angular跨域预飞405错误

老哥,我之前也碰到过一模一样的问题——不带认证时跨域请求正常,一加Basic Auth就炸出405错误,核心原因是浏览器发送的OPTIONS预飞请求被SonarQube的Tomcat直接拒绝了。你之前改web.xml的思路是对的,但可能配置不全,尤其是没覆盖预飞请求需要的关键参数。

下面是我实测有效的完整解决方案:

1. 给SonarQube的web.xml补全CorsFilter配置

找到你SonarQube安装目录下的web/WEB-INF/web.xml,把下面这段配置加到现有filter的前面(确保优先级最高):

<filter>
  <filter-name>CorsFilter</filter-name>
  <filter-class>org.apache.catalina.filters.CorsFilter</filter-class>
  <init-param>
    <param-name>cors.allowed.origins</param-name>
    <param-value>http://localhost:4200</param-value>
  </init-param>
  <init-param>
    <param-name>cors.allowed.methods</param-name>
    <param-value>GET,POST,HEAD,OPTIONS,PUT,DELETE</param-value>
  </init-param>
  <init-param>
    <param-name>cors.allowed.headers</param-name>
    <param-value>Authorization,Content-Type,X-Requested-With,Accept,Origin,Access-Control-Request-Method,Access-Control-Request-Headers</param-value>
  </init-param>
  <init-param>
    <param-name>cors.exposed.headers</param-name>
    <param-value>Access-Control-Allow-Origin,Access-Control-Allow-Credentials</param-value>
  </init-param>
  <init-param>
    <param-name>cors.support.credentials</param-name>
    <param-value>true</param-value>
  </init-param>
  <init-param>
    <param-name>cors.preflight.maxage</param-name>
    <param-value>1800</param-value>
  </init-param>
</filter>
<filter-mapping>
  <filter-name>CorsFilter</filter-name>
  <url-pattern>/*</url-pattern>
</filter-mapping>

划重点的配置细节:

  • 别用*代替http://localhost:4200,带认证的跨域请求不允许通配符
  • cors.allowed.methods必须包含OPTIONS——这是浏览器预飞请求的核心方法,之前可能漏了
  • cors.allowed.headers要把Authorization和预飞会带的两个头都加上,不然Tomcat会拦截
  • cors.support.credentials设为true,让服务器接受带认证信息的跨域请求

2. 确认SonarQube的Basic Auth配置没毛病

如果你是用SonarQube内置的Basic Auth,检查conf/sonar.properties里的这两行:

sonar.web.javaAdditionalOpts=-Djava.security.auth.login.config=./conf/jaas.config
sonar.web.authenticator.class=org.sonar.server.authentication.BasicAuthenticator

要是你用的是外部认证(比如LDAP),也得确保认证组件不会拦截OPTIONS请求。

3. 必须重启SonarQube!

改完配置一定要完全关停SonarQube再启动,热加载不管用的,我之前踩过这个坑。

4. 调整Angular的请求代码

别忘了在Angular的请求里开启withCredentials,不然认证信息传不过去:

import { HttpClient, HttpHeaders } from '@angular/common/http';

// 把你的SonarQube账号密码转成Basic Auth格式
const authHeader = 'Basic ' + btoa('你的用户名:你的密码');
const headers = new HttpHeaders({ 'Authorization': authHeader });

// 发送请求时带上withCredentials
this.http.get('http://localhost:9000/api/projects/search', {
  headers,
  withCredentials: true
}).subscribe(res => {
  console.log('请求成功:', res);
}, err => {
  console.error('请求失败:', err);
});

排查小技巧

  • 用Postman手动发个OPTIONS请求到SonarQube的接口,看返回头里有没有Access-Control-Allow-Origin这些CORS头,没有的话就是配置没生效
  • 看SonarQube的logs/web.log,搜CorsFilter,看有没有加载失败的报错
  • 要是Angular开了代理,得在代理配置里也加上认证和CORS的处理,别让代理把请求头丢了

内容的提问来源于stack exchange,提问作者Gustavs

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:44:06