57 lines
1.9 KiB
Plaintext
57 lines
1.9 KiB
Plaintext
==============================================================================
|
|
docs/output/02-mvc-bridge.txt
|
|
The identical MVC CORS mapping plus one line: .cors(Customizer.withDefaults()).
|
|
Profile: mvcbridge
|
|
==============================================================================
|
|
|
|
$ curl -s localhost:8080/diag/chain
|
|
{
|
|
"profiles": [
|
|
"mvcbridge"
|
|
],
|
|
"chains": [
|
|
{
|
|
"size": 12,
|
|
"filters": [
|
|
"DisableEncodeUrlFilter",
|
|
"WebAsyncManagerIntegrationFilter",
|
|
"SecurityContextHolderFilter",
|
|
"HeaderWriterFilter",
|
|
"CorsFilter",
|
|
"LogoutFilter",
|
|
"BasicAuthenticationFilter",
|
|
"RequestCacheAwareFilter",
|
|
"SecurityContextHolderAwareRequestFilter",
|
|
"AnonymousAuthenticationFilter",
|
|
"ExceptionTranslationFilter",
|
|
"AuthorizationFilter"
|
|
]
|
|
}
|
|
]
|
|
}
|
|
|
|
$ curl -s -i -X OPTIONS http://localhost:8080/api/data \
|
|
-H 'Origin: https://spa.example.com' \
|
|
-H 'Access-Control-Request-Method: POST' \
|
|
-H 'Access-Control-Request-Headers: content-type,x-xsrf-token'
|
|
|
|
HTTP/1.1 200
|
|
Vary: Origin
|
|
Vary: Access-Control-Request-Method
|
|
Vary: Access-Control-Request-Headers
|
|
Access-Control-Allow-Origin: https://spa.example.com
|
|
Access-Control-Allow-Methods: GET,POST
|
|
Access-Control-Allow-Headers: content-type, x-xsrf-token
|
|
Access-Control-Allow-Credentials: true
|
|
Access-Control-Max-Age: 1800
|
|
X-Content-Type-Options: nosniff
|
|
X-XSS-Protection: 0
|
|
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
|
|
Pragma: no-cache
|
|
X-Frame-Options: DENY
|
|
|
|
# CorsFilter is now in the chain at order 1000, between HeaderWriterFilter (900)
|
|
# and CsrfFilter (1100), and it short-circuits the preflight before authorization
|
|
# ever sees it. Note Access-Control-Max-Age: 1800 - that default comes from MVC's
|
|
# CorsRegistration, not from CorsConfiguration.
|