Ensure local @CrossOrigin maxAge overrides global value

Prior to this commit, a method-level @CrossOrigin maxAge value did not
override a class-level @CrossOrigin maxAge value. This contradicts the
Javadoc for @CrossOrgin which states the following.

    For those attributes where only a single value can be accepted such
    as allowCredentials and maxAge, the local overrides the global
    value.

This commit ensures that a method-level @CrossOrigin maxAge value
overrides a class-level @CrossOrigin maxAge value.

Closes gh-26619
This commit is contained in:
GungnirLaevatain
2021-02-27 17:44:02 +08:00
committed by Sam Brannen
parent 428dbc43da
commit e8f685ecc8
4 changed files with 69 additions and 2 deletions

View File

@@ -338,7 +338,7 @@ public class RequestMappingHandlerMapping extends RequestMappingInfoHandlerMappi
"or an empty string (\"\"): current value is [" + allowCredentials + "]");
}
if (annotation.maxAge() >= 0 && config.getMaxAge() == null) {
if (annotation.maxAge() >= 0) {
config.setMaxAge(annotation.maxAge());
}
}

View File

@@ -29,6 +29,7 @@ import org.springframework.http.HttpMethod;
import org.springframework.http.HttpStatus;
import org.springframework.http.ResponseEntity;
import org.springframework.http.client.HttpComponentsClientHttpRequestFactory;
import org.springframework.stereotype.Controller;
import org.springframework.web.bind.annotation.CrossOrigin;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.PostMapping;
@@ -37,6 +38,7 @@ import org.springframework.web.bind.annotation.RequestMethod;
import org.springframework.web.bind.annotation.RestController;
import org.springframework.web.client.HttpClientErrorException;
import org.springframework.web.client.RestTemplate;
import org.springframework.web.cors.CorsConfiguration;
import org.springframework.web.reactive.config.EnableWebFlux;
import org.springframework.web.testfixture.http.server.reactive.bootstrap.HttpServer;
@@ -257,6 +259,19 @@ class CrossOriginAnnotationIntegrationTests extends AbstractRequestMappingIntegr
assertThat(entity.getHeaders().getAccessControlAllowCredentials()).isTrue();
}
@ParameterizedHttpServerTest
void maxAgeWithDefaultOrigin(HttpServer httpServer) throws Exception {
startServer(httpServer);
this.headers.add(HttpHeaders.ACCESS_CONTROL_REQUEST_METHOD, "GET");
ResponseEntity<String> entity = performOptions("/classAge", this.headers, String.class);
assertThat(entity.getStatusCode()).isEqualTo(HttpStatus.OK);
assertThat(entity.getHeaders().getAccessControlMaxAge()).isEqualTo(10);
entity = performOptions("/methodAge", this.headers, String.class);
assertThat(entity.getStatusCode()).isEqualTo(HttpStatus.OK);
assertThat(entity.getHeaders().getAccessControlMaxAge()).isEqualTo(100);
}
@Configuration
@EnableWebFlux
@@ -361,4 +376,21 @@ class CrossOriginAnnotationIntegrationTests extends AbstractRequestMappingIntegr
}
}
@RestController
@CrossOrigin(maxAge = 10)
private static class MaxAgeWithDefaultOriginController {
@CrossOrigin
@GetMapping(path = "/classAge")
public String classAge() {
return "classAge";
}
@CrossOrigin(maxAge = 100)
@GetMapping(path = "/methodAge")
public String methodAge() {
return "methodAge";
}
}
}

View File

@@ -456,7 +456,7 @@ public class RequestMappingHandlerMapping extends RequestMappingInfoHandlerMappi
"or an empty string (\"\"): current value is [" + allowCredentials + "]");
}
if (annotation.maxAge() >= 0 && config.getMaxAge() == null) {
if (annotation.maxAge() >= 0) {
config.setMaxAge(annotation.maxAge());
}
}

View File

@@ -310,6 +310,27 @@ public class CrossOriginTests {
assertThat(this.handlerMapping.getHandler(request)).isNull();
}
@Test
public void maxAgeWithDefaultOrigin() throws Exception {
this.handlerMapping.registerHandler(new MaxAgeWithDefaultOriginController());
this.request.setRequestURI("/classAge");
HandlerExecutionChain chain = this.handlerMapping.getHandler(request);
CorsConfiguration config = getCorsConfiguration(chain, false);
assertThat(config).isNotNull();
assertThat(config.getAllowedMethods()).containsExactly("GET");
assertThat(config.getAllowedOrigins()).containsExactly("*");
assertThat(config.getMaxAge()).isEqualTo(10);
this.request.setRequestURI("/methodAge");
chain = this.handlerMapping.getHandler(request);
config = getCorsConfiguration(chain, false);
assertThat(config).isNotNull();
assertThat(config.getAllowedMethods()).containsExactly("GET");
assertThat(config.getAllowedOrigins()).containsExactly("*");
assertThat(config.getMaxAge()).isEqualTo(100);
}
private CorsConfiguration getCorsConfiguration(HandlerExecutionChain chain, boolean isPreFlightRequest) {
if (isPreFlightRequest) {
@@ -425,7 +446,21 @@ public class CrossOriginTests {
@RequestMapping(path = "/baz", method = RequestMethod.GET)
public void baz() {
}
}
@Controller
@CrossOrigin(maxAge = 10)
private static class MaxAgeWithDefaultOriginController {
@CrossOrigin
@RequestMapping(path = "/classAge", method = RequestMethod.GET)
public void classAge() {
}
@CrossOrigin(maxAge = 100)
@RequestMapping(path = "/methodAge", method = RequestMethod.GET)
public void methodAge() {
}
}