==============================================================================
docs/output/03-security-source.txt
A @Bean named corsConfigurationSource. .cors(..) is never called - it is applied for us.
Profile: securitysource
==============================================================================

$ curl -s localhost:8080/diag/cors-sources
{
    "corsConfigurationSourceBeans": {
        "corsConfigurationSource": "UrlBasedCorsConfigurationSource",
        "mvcHandlerMappingIntrospector": "HandlerMappingIntrospector"
    },
    "hasBeanNamedCorsConfigurationSource": true
}

$ curl -s -i -X OPTIONS http://localhost:8080/api/data \
    -H 'Origin: https://spa.example.com' \
    -H 'Access-Control-Request-Method: POST' \
    -H 'Access-Control-Request-Headers: content-type,x-xsrf-token'

HTTP/1.1 200 
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Access-Control-Allow-Origin: https://spa.example.com
Access-Control-Allow-Methods: GET,POST
Access-Control-Allow-Headers: content-type, x-xsrf-token
Access-Control-Allow-Credentials: true
X-Content-Type-Options: nosniff
X-XSS-Protection: 0
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
X-Frame-Options: DENY

# Compare with 02: there is no Access-Control-Max-Age here. CorsConfiguration
# leaves maxAge null, so every single cross-origin call re-runs the preflight.
