springboot項目實現(xiàn)配置跨域
在Spring Boot項目中配置跨域(CORS,Cross-Origin Resource Sharing)主要是為了允許來自不同源(不同的協(xié)議、域名或端口)的前端應(yīng)用能夠訪問后端API。
Spring Boot提供了多種方式來配置跨域支持。
1. 使用@CrossOrigin注解
最簡單的方式是在控制器或者具體的方法上使用@CrossOrigin注解。
例如:
import org.springframework.web.bind.annotation.CrossOrigin;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;
@RestController
@CrossOrigin(origins = "http://example.com") // 允許來自 http://example.com 的跨域請求
public class MyController {
@GetMapping("/myEndpoint")
public String myMethod() {
return "Hello, World!";
}
}這將允許來自http://example.com的跨域請求訪問/myEndpoint這個接口。
2. 全局跨域配置
如果你想要為整個應(yīng)用配置跨域支持,可以在配置類中添加一個WebMvcConfigurer的實現(xiàn):
import org.springframework.context.annotation.Configuration;
import org.springframework.web.servlet.config.annotation.CorsRegistry;
import org.springframework.web.servlet.config.annotation.WebMvcConfigurer;
@Configuration
public class WebConfig implements WebMvcConfigurer {
@Override
public void addCorsMappings(CorsRegistry registry) {
registry.addMapping("/**") // 為所有請求添加跨域支持
.allowedOrigins("*") // 允許任何源
.allowedMethods("GET", "POST", "PUT", "DELETE") // 允許的HTTP方法
.allowCredentials(true); // 是否允許發(fā)送Cookie信息
}
}這個配置將允許任何源的跨域請求,并且允許GET、POST、PUT和DELETE方法。
allowCredentials設(shè)置為true表示允許客戶端發(fā)送Cookie信息。
3. 使用CorsFilter
如果需要更細(xì)致的控制,可以創(chuàng)建一個CorsFilter并注冊為Bean:
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.cors.CorsConfiguration;
import org.springframework.web.cors.CorsConfigurationSource;
import org.springframework.web.cors.UrlBasedCorsConfigurationSource;
import org.springframework.web.filter.CorsFilter;
@Configuration
public class CorsConfig {
@Bean
public CorsFilter corsFilter() {
CorsConfiguration configuration = new CorsConfiguration();
configuration.setAllowedOrigins("*");
configuration.setAllowedMethods("GET", "POST", "PUT", "DELETE");
configuration.setAllowCredentials(true);
configuration.setAllowedHeaders("*");
UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
source.registerCorsConfiguration("/**", configuration);
return new CorsFilter(source);
}
}這個配置與上面的全局跨域配置類似,但是通過CorsFilter提供了更多的靈活性和控制。
注意事項:
allowedOrigins可以是一個具體的域名,如"http://example.com",或者使用"*"來允許任何源。allowedMethods定義了允許的HTTP方法。allowCredentials設(shè)置為true時,服務(wù)器將接受包含敏感信息(如Cookies和HTTP認(rèn)證信息)的跨域請求。allowedHeaders定義了允許的HTTP請求頭。
根據(jù)你的項目需求和安全考慮,合理配置跨域支持是非常重要的。
在生產(chǎn)環(huán)境中,通常不建議允許任何源("*"),而是應(yīng)該明確指定可信的源。
當(dāng)然,除了上述提到的使用@CrossOrigin注解、全局跨域配置和CorsFilter之外,還有其他一些方法可以在Spring Boot項目中配置跨域支持。
4. 配置WebMvcConfigurerProperties
在Spring Boot中,可以通過擴展WebMvcConfigurerProperties類來配置跨域。
首先,需要創(chuàng)建一個配置類并繼承WebMvcConfigurerProperties:
import org.springframework.boot.context.properties.ConfigurationProperties;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.servlet.config.annotation.WebMvcConfigurer;
@Configuration
@ConfigurationProperties(prefix = "cors")
public class CorsConfig implements WebMvcConfigurer {
private String[] allowedOrigins;
private String[] allowedMethods;
private String[] allowedHeaders;
private boolean allowCredentials;
// getters and setters ...
@Override
public void addCorsMappings(CorsRegistry registry) {
registry.addMapping("/**")
.allowedOrigins(allowedOrigins)
.allowedMethods(allowedMethods)
.allowedHeaders(allowedHeaders)
.allowCredentials(allowCredentials);
}
}然后,在application.properties或application.yml中添加相應(yīng)的配置:
# application.properties cors.allowedOrigins[0]=http://example.com cors.allowedMethods[0]=GET cors.allowedMethods[1]=POST cors.allowedHeaders[0]=Content-Type cors.allowCredentials=true
5. 使用Spring Security
如果你的項目中使用了Spring Security,可以通過配置HttpSecurity來實現(xiàn)跨域支持。
首先,需要創(chuàng)建一個配置類并重寫configure(HttpSecurity http)方法:
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {
@Override
protected void configure(HttpSecurity http) throws Exception {
http
// ...其他配置...
.cors().and() // 啟用默認(rèn)的跨域配置
// ...其他配置...
}
}如果需要自定義跨域配置,可以使用.cors()方法并傳遞一個CorsConfigurationSource實例:
CorsConfiguration configuration = new CorsConfiguration();
configuration.setAllowedOrigins(Arrays.asList("http://example.com"));
configuration.setAllowedMethods(Arrays.asList("GET","POST", "PUT", "DELETE"));
configuration.setAllowedHeaders(Arrays.asList("Content-Type", "Authorization"));
configuration.setAllowCredentials(true);
UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
source.registerCorsConfiguration("/**", configuration);
http.cors(source).and();6. 使用第三方庫
還可以使用第三方庫如cors-filter來實現(xiàn)跨域支持。
這通常需要在項目的pom.xml中添加依賴,并在web.xml中配置過濾器。
以上是一些在Spring Boot項目中配置跨域支持的方法。
選擇最適合項目需求和架構(gòu)的方法,并確保考慮到安全性和性能的影響。
在實施跨域策略時,應(yīng)當(dāng)避免過度寬松的配置,以免引入安全風(fēng)險。
這些僅為個人經(jīng)驗,希望能給大家一個參考,也希望大家多多支持腳本之家。
相關(guān)文章
深入理解happens-before和as-if-serial語義
本文大部分整理自《Java并發(fā)編程的藝術(shù)》,溫故而知新,加深對基礎(chǔ)的理解程度。下面可以和小編來一起學(xué)習(xí)下2019-05-05
Java?18?新特性之Web服務(wù)器?jwebserver功能
JEP?408:?Simple?Web?Server,是這次Java?18推出的一個比較獨立的全新功能點。我們可以通過命令行工具來啟動一個提供靜態(tài)資源訪問的迷你Web服務(wù)器,本文通過一個構(gòu)建HTML頁面的例子,來嘗試一下jwebserver的功能2022-04-04
SpringBoot中使用Redis對接口進行限流的實現(xiàn)
本文將結(jié)合實例代碼,介紹SpringBoot中使用Redis對接口進行限流的實現(xiàn),具有一定的參考價值,感興趣的小伙伴們可以參考一下2021-07-07
MyBatis使用annonation定義類型映射的簡易用法示例
這篇文章主要介紹了MyBatis使用annonation定義類型映射的簡易用法示例詳解,有需要的朋友可以借鑒參考下,希望能夠有所幫助,祝大家多多進步,早日升職加薪2023-09-09

