(Forty-one) java micro edition spring cloud service architecture b2b2c e-commerce platform - front-end solution for cross-domain problems

When we need a way to spring boot restful interface external service provider, if this time around the end of the separation of architecture is, it will involve cross-domain problems, how to solve the problem of cross-domain, here come To investigate this question.

Solution one: Add @CrossOrigin comment on the Controller

Used as follows:

@CrossOrigin // 注解方式
@RestController
public class HandlerScanController {
	
	
	@CrossOrigin(allowCredentials="true", allowedHeaders="*", methods={RequestMethod.GET,
			RequestMethod.POST, RequestMethod.DELETE, RequestMethod.OPTIONS,
			RequestMethod.HEAD, RequestMethod.PUT, RequestMethod.PATCH}, origins="*")
	@PostMapping("/confirm")
	public Response handler(@RequestBody Request json){
		
		return null;
	}
}

Solution two: Global

code show as below:

@Configuration
	public class MyConfiguration {
 
	    @Bean
	    public WebMvcConfigurer corsConfigurer() {
	        return new WebMvcConfigurerAdapter() {
	            @Override
	            public void addCorsMappings(CorsRegistry registry) {
	                registry.addMapping("/**")
	                .allowCredentials(true)
	                .allowedMethods("GET");
	            }
	        };
	    }
	}

Solution three: Use in conjunction with Filter

In spring boot main class, add a CorsFilter

/**
     * 
     * attention:简单跨域就是GET,HEAD和POST请求,但是POST请求的"Content-Type"只能是application/x-www-form-urlencoded, multipart/form-data 或 text/plain
     * 反之,就是非简单跨域,此跨域有一个预检机制,说直白点,就是会发两次请求,一次OPTIONS请求,一次真正的请求
     */
    @Bean
    public CorsFilter corsFilter() {
        final UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
        final CorsConfiguration config = new CorsConfiguration();
        config.setAllowCredentials(true); // 允许cookies跨域
        config.addAllowedOrigin("*");// #允许向该服务器提交请求的URI,*表示全部允许,在SpringMVC中,如果设成*,会自动转成当前请求头中的Origin
        config.addAllowedHeader("*");// #允许访问的头信息,*表示全部
        config.setMaxAge(18000L);// 预检请求的缓存时间(秒),即在这个时间段里,对于相同的跨域请求不会再预检了
        config.addAllowedMethod("OPTIONS");// 允许提交请求的方法,*表示全部允许
        config.addAllowedMethod("HEAD");
        config.addAllowedMethod("GET");// 允许Get的请求方法
        config.addAllowedMethod("PUT");
        config.addAllowedMethod("POST");
        config.addAllowedMethod("DELETE");
        config.addAllowedMethod("PATCH");
        source.registerCorsConfiguration("/**", config);
        return new CorsFilter(source);
    }

Guess you like

Origin blog.csdn.net/vvx0206/article/details/95164444