Add the cors-csrf module
This commit is contained in:
56
cors-csrf/docs/output/02-mvc-bridge.txt
Normal file
56
cors-csrf/docs/output/02-mvc-bridge.txt
Normal file
@@ -0,0 +1,56 @@
|
||||
==============================================================================
|
||||
docs/output/02-mvc-bridge.txt
|
||||
The identical MVC CORS mapping plus one line: .cors(Customizer.withDefaults()).
|
||||
Profile: mvcbridge
|
||||
==============================================================================
|
||||
|
||||
$ curl -s localhost:8080/diag/chain
|
||||
{
|
||||
"profiles": [
|
||||
"mvcbridge"
|
||||
],
|
||||
"chains": [
|
||||
{
|
||||
"size": 12,
|
||||
"filters": [
|
||||
"DisableEncodeUrlFilter",
|
||||
"WebAsyncManagerIntegrationFilter",
|
||||
"SecurityContextHolderFilter",
|
||||
"HeaderWriterFilter",
|
||||
"CorsFilter",
|
||||
"LogoutFilter",
|
||||
"BasicAuthenticationFilter",
|
||||
"RequestCacheAwareFilter",
|
||||
"SecurityContextHolderAwareRequestFilter",
|
||||
"AnonymousAuthenticationFilter",
|
||||
"ExceptionTranslationFilter",
|
||||
"AuthorizationFilter"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
$ curl -s -i -X OPTIONS http://localhost:8080/api/data \
|
||||
-H 'Origin: https://spa.example.com' \
|
||||
-H 'Access-Control-Request-Method: POST' \
|
||||
-H 'Access-Control-Request-Headers: content-type,x-xsrf-token'
|
||||
|
||||
HTTP/1.1 200
|
||||
Vary: Origin
|
||||
Vary: Access-Control-Request-Method
|
||||
Vary: Access-Control-Request-Headers
|
||||
Access-Control-Allow-Origin: https://spa.example.com
|
||||
Access-Control-Allow-Methods: GET,POST
|
||||
Access-Control-Allow-Headers: content-type, x-xsrf-token
|
||||
Access-Control-Allow-Credentials: true
|
||||
Access-Control-Max-Age: 1800
|
||||
X-Content-Type-Options: nosniff
|
||||
X-XSS-Protection: 0
|
||||
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
|
||||
Pragma: no-cache
|
||||
X-Frame-Options: DENY
|
||||
|
||||
# CorsFilter is now in the chain at order 1000, between HeaderWriterFilter (900)
|
||||
# and CsrfFilter (1100), and it short-circuits the preflight before authorization
|
||||
# ever sees it. Note Access-Control-Max-Age: 1800 - that default comes from MVC's
|
||||
# CorsRegistration, not from CorsConfiguration.
|
||||
Reference in New Issue
Block a user