1
0

Add the cors-csrf module

This commit is contained in:
2026-08-28 09:33:22 +05:30
parent 73ab67b171
commit cad813e1ae
49 changed files with 3338 additions and 13 deletions

View File

@@ -10,37 +10,45 @@ by that module's `scripts/run-all.sh`, never typed by hand.
| [`context-propagation/`](context-propagation/README.md) | [Spring Security Context Propagation: The Complete Guide](https://ankurm.com/spring-security-context-propagation-complete-guide/) | Whether a `SecurityContext` survives `@Async`, executors, virtual threads, `StructuredTaskScope`, Reactor, schedulers and the servlet filter chain |
| [`method-security/`](method-security/README.md) | [Method Security in Spring Security 7: `@PreAuthorize`, `@PostAuthorize` and the Proxy Traps](https://ankurm.com/spring-security-7-method-security-proxy-traps/) | What the method-security annotations do, the full SpEL surface, and the cases where the check silently does not run |
| [`filter-chain/`](filter-chain/README.md) | [The Spring Security Filter Chain Explained](https://ankurm.com/spring-security-filter-chain-explained/) | Every filter in the default chain and its order number, where a custom filter actually lands, and how to read the TRACE log |
| [`cors-csrf/`](cors-csrf/README.md) | [CORS, CSRF and SameSite in Spring Boot 4](https://ankurm.com/spring-boot-4-cors-csrf-samesite/) | Why MVC-layer CORS does not fix a security-layer preflight rejection, what `csrf.spa()` assigns, and the cookie a browser silently refuses to store |
The three are related more closely than they look. `filter-chain` is about how an
`Authentication` gets into `SecurityContextHolder` in the first place and in what order;
`context-propagation` is about whether it survives leaving the request thread; `method-security`
reads it back on whatever thread it ends up on. An `@Async` method carrying `@PreAuthorize` fails
with `AuthenticationCredentialsNotFoundException` for reasons that belong to the second module,
not the third — and a custom authentication filter that never populated the context in the first
They are related more closely than they look. `filter-chain` is about how an `Authentication`
gets into `SecurityContextHolder` in the first place and in what order; `context-propagation` is
about whether it survives leaving the request thread; `method-security` reads it back on whatever
thread it ends up on. An `@Async` method carrying `@PreAuthorize` fails with
`AuthenticationCredentialsNotFoundException` for reasons that belong to the second module, not
the third — and a custom authentication filter that never populated the context in the first
place fails the same way, for reasons that belong to the first.
`cors-csrf` is where those order numbers stop being trivia. `CorsFilter` at 1000 and `CsrfFilter`
at 1100 both sit far above `AuthorizationFilter` at 4200, and almost every confusing symptom in
that module is a consequence of one of those three positions — including a 403 that arrives as a
401 because the container re-dispatched the request to `/error` and the chain ran a second time.
## Common ground
All three modules target the same verified stack: **JDK 25** (Temurin 25.0.4.1+1),
All modules target the same verified stack: **JDK 25** (Temurin 25.0.4.1+1),
**Spring Framework 7.0.9**, **Spring Security 7.1.1** — the versions Spring Boot **4.1.1**
manages. Versions were taken from `maven-metadata.xml` on Maven Central rather than from
release announcements.
`context-propagation` additionally needs `--enable-preview`, because `StructuredTaskScope` is
still a preview API on JDK 25. `method-security` does not. `filter-chain` is the only module
that is a real servlet application: it inherits `spring-boot-starter-parent` and runs on Tomcat,
because the thing it demonstrates only exists inside a servlet container.
still a preview API on JDK 25. `method-security` does not. `filter-chain` and `cors-csrf` are
real servlet applications: they inherit `spring-boot-starter-parent` and run on Tomcat, because
the things they demonstrate only exist inside a servlet container.
## Running a module
```bash
cd method-security # or context-propagation, or filter-chain
cd cors-csrf # or context-propagation, method-security, filter-chain
./scripts/run-all.sh # every demo plus the test suite, regenerating docs/output/
mvn test # just the assertions
```
`filter-chain` also has `./scripts/run.sh <profile>` and `./scripts/stop.sh`, because its
scenarios are a running web application rather than a `main()` method.
`filter-chain` and `cors-csrf` also have `./scripts/run.sh <profile>` and `./scripts/stop.sh`,
because their scenarios are a running web application rather than a `main()` method.
`cors-csrf` adds `./scripts/preflight.sh`, which sends one CORS preflight and prints the headers
that decide the outcome.
## License