Align default values with 5.0.x

Closes gh-25414
This commit is contained in:
Rossen Stoyanchev
2020-07-20 06:32:38 +03:00
parent 6d524e1da5
commit 70773468c2
7 changed files with 42 additions and 30 deletions

View File

@@ -24,6 +24,13 @@ implementation (https://github.com/spring-projects/spring-framework/blob/master/
by default) in order to add the relevant CORS response headers (like `Access-Control-Allow-Origin`)
based on the CORS configuration you have provided.
[NOTE]
====
Be aware that cookies are not allowed by default to avoid increasing the surface attack of
the web application (for example via exposing sensitive user-specific information like
CSRF tokens). Set `allowedCredentials` property to `true` in order to allow them.
====
[NOTE]
====
Since CORS requests are automatically dispatched, you *do not need* to change the
@@ -151,7 +158,8 @@ public class WebConfig extends WebMvcConfigurerAdapter {
.allowedMethods("PUT", "DELETE")
.allowedHeaders("header1", "header2", "header3")
.exposedHeaders("header1", "header2")
.allowCredentials(false).maxAge(3600);
.allowCredentials(true)
.maxAge(3600);
}
}
----
@@ -180,7 +188,7 @@ It is also possible to declare several CORS mappings with customized properties:
allowed-origins="https://domain1.com, https://domain2.com"
allowed-methods="GET, PUT"
allowed-headers="header1, header2, header3"
exposed-headers="header1, header2" allow-credentials="false"
exposed-headers="header1, header2"
max-age="123" />
<mvc:mapping path="/resources/**"