cors java 安全问题_Cors实现java后端完全跨域

https://blog.coding.net/blog/spring-mvc-cors 这篇文章很详细的介绍了JS的跨域,给出的解决方案是springboot的方式,假如不用spring boot 或者 spring版本低于4.2就需要自己实现;

参考了spring boot的实现方式,并有所简化,代码如下:

package com.lvluo.web.filter.CorsFilter;

import java.io.IOException;

import javax.servlet.Filter;

import javax.servlet.FilterChain;

import javax.servlet.FilterConfig;

import javax.servlet.ServletException;

import javax.servlet.ServletRequest;

import javax.servlet.ServletResponse;

import javax.servlet.http.HttpServletRequest;

import javax.servlet.http.HttpServletResponse;

import org.springframework.http.HttpHeaders;

public class CorsFilter implements Filter {

public static final String ACCESS_CONTROL_REQUEST_METHOD = "Access-Control-Request-Method";

public static final String OPTIONS = "OPTIONS";

public void doFilter(ServletRequest request, ServletResponse response,

FilterChain chain) throws IOException, ServletException {

HttpServletRequest httpRequest = (HttpServletRequest) request;

HttpServletResponse httpResponse = (HttpServletResponse) response;

if (isCorsRequest(httpRequest)) {

httpResponse.setHeader("Access-Control-Allow-Origin", "*");

httpResponse.setHeader("Access-Control-Allow-Methods",

"POST, GET, PUT, DELETE");

httpResponse.setHeader("Access-Control-Allow-Credentials", "true");

// response.setIntHeader("Access-Control-Max-Age", 1728000);

httpResponse

.setHeader(

"Access-Control-Allow-Headers",

"Origin, X-Requested-With, Content-Type, Accept, Accept-Encoding, Authorization");

if (isPreFlightRequest(httpRequest)) {

return;

}

}

chain.doFilter(request, response);

}

public void init(FilterConfig filterConfig) {

}

public void destroy() {

}

public boolean isCorsRequest(HttpServletRequest request) {

return (request.getHeader(HttpHeaders.ORIGIN) != null);

}

/**

* Returns {@code true} if the request is a valid CORS pre-flight one.

*/

public boolean isPreFlightRequest(HttpServletRequest request) {

return (isCorsRequest(request) && OPTIONS.equals(request.getMethod()) && request

.getHeader(ACCESS_CONTROL_REQUEST_METHOD) != null);

}

}

接着在web.xml配置filter即可

corsFilter

com.lvluo.web.filter.CorsFilter

corsFilter

/api/*

前端测试的JS代码,其中客户端的

$.ajax({

headers : {

'Authorization' :'Bearer iBoxSO9QdrHR0'

},

url: 'http://localhost:8080/service/api/ping',

type: 'GET',

dataType: 'json',

success : function(result){

$("#result").html(result.code);

}

})

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值