Align default values with 5.0.x
Closes gh-25414
This commit is contained in:
@@ -24,6 +24,13 @@ implementation (https://github.com/spring-projects/spring-framework/blob/master/
|
||||
by default) in order to add the relevant CORS response headers (like `Access-Control-Allow-Origin`)
|
||||
based on the CORS configuration you have provided.
|
||||
|
||||
[NOTE]
|
||||
====
|
||||
Be aware that cookies are not allowed by default to avoid increasing the surface attack of
|
||||
the web application (for example via exposing sensitive user-specific information like
|
||||
CSRF tokens). Set `allowedCredentials` property to `true` in order to allow them.
|
||||
====
|
||||
|
||||
[NOTE]
|
||||
====
|
||||
Since CORS requests are automatically dispatched, you *do not need* to change the
|
||||
@@ -151,7 +158,8 @@ public class WebConfig extends WebMvcConfigurerAdapter {
|
||||
.allowedMethods("PUT", "DELETE")
|
||||
.allowedHeaders("header1", "header2", "header3")
|
||||
.exposedHeaders("header1", "header2")
|
||||
.allowCredentials(false).maxAge(3600);
|
||||
.allowCredentials(true)
|
||||
.maxAge(3600);
|
||||
}
|
||||
}
|
||||
----
|
||||
@@ -180,7 +188,7 @@ It is also possible to declare several CORS mappings with customized properties:
|
||||
allowed-origins="https://domain1.com, https://domain2.com"
|
||||
allowed-methods="GET, PUT"
|
||||
allowed-headers="header1, header2, header3"
|
||||
exposed-headers="header1, header2" allow-credentials="false"
|
||||
exposed-headers="header1, header2"
|
||||
max-age="123" />
|
||||
|
||||
<mvc:mapping path="/resources/**"
|
||||
|
||||
Reference in New Issue
Block a user