记一次后端跨域处理

Access to XMLHttpRequest at 'http://xxx.xxx.xxx.xxx:8081/user/login' from origin http://xxx.xxx.xxx.xxx:8082' has been blocked by CORS policy: Response to preflight request doesn't pass access control check: It does not have HTTP ok status.

 

 

由于使用的是shiro集成springboot,所以使用如下配置没有生效。如果单独的使用springboot,使用该方法跨域是可以的。

  @Bean
  public CorsFilter corsFilter() {
    UrlBasedCorsConfigurationSource source = new
            UrlBasedCorsConfigurationSource();
    CorsConfiguration config = new CorsConfiguration();
    config.setAllowCredentials(true);
//    config.addAllowedOrigin("*");
    config.addAllowedHeader("*");
    config.addAllowedMethod("*");
    config.setAllowedOrigins(allowedOrigins);
    source.registerCorsConfiguration("/**", config);
    return new CorsFilter(source);
  }

所以修改为了如下过滤器,原因是跨域过滤器可以先与jwtFilter过滤器执行。测试有效

@Component
public class CorsFilter implements Filter {

    @Override
    public void init(FilterConfig filterConfig) throws ServletException {
    }

    @Override
    public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException {
        HttpServletResponse response = (HttpServletResponse) servletResponse;
        HttpServletRequest request = (HttpServletRequest) servletRequest;

        response.setHeader("Access-Control-Allow-Origin", request.getHeader("Origin"));
        response.setHeader("Access-Control-Allow-Headers", request.getHeader("Access-Control-Request-Headers"));
        response.setHeader("Access-Control-Allow-Methods", "*");
        response.setHeader("Access-Control-Max-Age", "3600");
        response.setHeader("Access-Control-Allow-Credentials", "true");

        // 跨域时会首先发送一个option请求,这里我们给option请求直接返回正常状态
        if (request.getMethod().equals(RequestMethod.OPTIONS.name())) {
            response.setStatus(HttpStatus.OK.value());
            return;
        }

        filterChain.doFilter(request, response);
    }

    @Override
    public void destroy() {

    }
}

跨域其他问题:

The 'Access-Control-Allow-Origin' header contains multiple values '*, *', but only one is allowed。

主要为niginx配置了跨域,后端有重复配置引起,两者去除之一就行

 

参考文档:

https://blog.csdn.net/weixin_39973810/article/details/85786693

https://blog.csdn.net/qq_28082757/article/details/101017679

https://blog.csdn.net/poem_2010/article/details/86382559

https://blog.csdn.net/q646926099/article/details/79082204

https://blog.csdn.net/madonghyu/article/details/80027387

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值