栏目分类:
子分类:
返回
名师互学网用户登录
快速导航关闭
当前搜索
当前分类
子分类
实用工具
热门搜索
名师互学网 > IT > 面试经验 > 面试问答

Spring Boot Security CORS

面试问答 更新时间: 发布时间: IT归档 最新发布 模块sitemap 名妆网 法律咨询 聚返吧 英语巴士网 伯小乐 网商动力

Spring Boot Security CORS

您可以编写自己的CorsFilter并将其添加到安全配置中,而不必使用CorsRegistry。

自定义CorsFilter类:

public class CorsFilter implements Filter {    @Override    public void init(FilterConfig filterConfig) throws ServletException {    }    @Override    public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException {        HttpServletResponse response = (HttpServletResponse) servletResponse;        HttpServletRequest request= (HttpServletRequest) servletRequest;        response.setHeader("Access-Control-Allow-Origin", "*");        response.setHeader("Access-Control-Allow-Methods", "GET,POST,DELETE,PUT,OPTIONS");        response.setHeader("Access-Control-Allow-Headers", "*");        response.setHeader("Access-Control-Allow-Credentials", true);        response.setHeader("Access-Control-Max-Age", 180);        filterChain.doFilter(servletRequest, servletResponse);    }    @Override    public void destroy() {    }}

安全配置类:

@Configuration@EnableWebSecuritypublic class OAuth2SecurityConfiguration extends WebSecurityConfigurerAdapter {    @Bean    CorsFilter corsFilter() {        CorsFilter filter = new CorsFilter();        return filter;    }    @Override    protected void configure(HttpSecurity http) throws Exception {        http     .addFilterBefore(corsFilter(), SessionManagementFilter.class) //adds your custom CorsFilter     .exceptionHandling().authenticationEntryPoint(authenticationEntryPoint).and()     .formLogin()         .successHandler(ajaxSuccessHandler)         .failureHandler(ajaxFailureHandler)         .loginProcessingUrl("/authentication")         .passwordParameter("password")         .usernameParameter("username")     .and()     .logout()         .deletecookies("JSESSIONID")         .invalidateHttpSession(true)         .logoutUrl("/logout")         .logoutSuccessUrl("/")     .and()     .csrf().disable()     .anonymous().disable()     .authorizeRequests()     .antMatchers("/authentication").permitAll()     .antMatchers("/oauth/token").permitAll()     .antMatchers("/admin/*").access("hasRole('ROLE_ADMIN')")     .antMatchers("/user/*").access("hasRole('ROLE_USER')");    }}


转载请注明:文章转载自 www.mshxw.com
本文地址:https://www.mshxw.com/it/405484.html
我们一直用心在做
关于我们 文章归档 网站地图 联系我们

版权所有 (c)2021-2022 MSHXW.COM

ICP备案号:晋ICP备2021003244-6号