You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot 3.3.1多租户场景下多Origin跨域403问题排查求助

Spring Boot 3.3.1多租户场景下多Origin跨域403问题排查求助

各位技术大佬们,我被一个跨域问题卡了30多个小时,实在没辙了,来求助大家!

我的后端是Java Spring Boot 3.3.1的多租户架构,第一个基于React(Vite)开发的前端访问完全正常,但第二个新的React前端一直报403 CORS错误,实在搞不懂哪里出问题了。

后端相关配置细节

POM依赖片段

<dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-web</artifactId>
        <version>3.3.1</version>
    </dependency>

<dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-security</artifactId>
        <version>3.3.1</version>
    </dependency>

安全配置(AppConfig)核心代码

@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
    http
            .csrf(AbstractHttpConfigurer::disable)
            .addFilterBefore(firebaseAuthenticationFilter, UsernamePasswordAuthenticationFilter.class)
            .sessionManagement(session -> session.sessionCreationPolicy(SessionCreationPolicy.IF_REQUIRED))
            .authorizeHttpRequests(authorizeRequests -> authorizeRequests
                    .requestMatchers("/api/whoami").permitAll()
                    .requestMatchers(HttpMethod.GET, "/api/products/**").permitAll()
                    .requestMatchers(HttpMethod.POST, "/api/messages").permitAll()
                    .requestMatchers(HttpMethod.POST, "/api/email").permitAll()
                    .requestMatchers("/api/**").authenticated()
                    .anyRequest().authenticated()
            )
            .logout(LogoutConfigurer::permitAll)
            .cors(cors -> cors.configurationSource(corsConfigurationSource()));

    return http.build();
}

@Bean
public CorsConfigurationSource corsConfigurationSource() {
    CorsConfiguration configuration = new CorsConfiguration();
    configuration.setAllowedOriginPatterns(List.of("*"));
    configuration.setAllowedMethods(List.of("GET", "POST", "PUT", "DELETE", "OPTIONS"));
    configuration.setAllowedHeaders(List.of("Content-Type", "X-Tenant-ID", "Authorization", "Ocp-Apim-Subscription-Key"));
    configuration.setExposedHeaders(List.of("Authorization", "Ocp-Apim-Subscription-Key"));
    configuration.setAllowCredentials(true);
    configuration.setMaxAge(3600L);

    UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
    source.registerCorsConfiguration("/**", configuration);
    return source;
}

已完成的排查操作

  • 一开始是指定具体允许的域名,现在为了排查已经放开成允许所有Origin(setAllowedOriginPatterns(List.of("*"))),但问题依旧
  • 后端部署在Azure App Service,已经清空了Azure平台自带的CORS规则,避免和代码里的配置冲突
  • 特意解压了Azure上的Jar包,确认AppConfig的配置和本地完全一致,没有被意外篡改
  • Postman测试对比:用第一个前端的Origin请求接口能正常返回200/201,但用新前端的Origin就直接报403 CORS错误,这逻辑完全说不通啊
  • 两个React(Vite)前端都部署在Azure静态Web App上

求助疑问

有没有大佬能指点下我哪里漏了?还有什么检查点可以试试?需要其他信息的话随时说,万分感谢!

备注:内容来源于stack exchange,提问作者Peter H

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.14 11:53:01