Ensure local @CrossOrigin maxAge overrides global value
Prior to this commit, a method-level @CrossOrigin maxAge value did not
override a class-level @CrossOrigin maxAge value. This contradicts the
Javadoc for @CrossOrgin which states the following.
For those attributes where only a single value can be accepted such
as allowCredentials and maxAge, the local overrides the global
value.
This commit ensures that a method-level @CrossOrigin maxAge value
overrides a class-level @CrossOrigin maxAge value.
Closes gh-26619
This commit is contained in:
committed by
Sam Brannen
parent
428dbc43da
commit
e8f685ecc8
@@ -338,7 +338,7 @@ public class RequestMappingHandlerMapping extends RequestMappingInfoHandlerMappi
|
||||
"or an empty string (\"\"): current value is [" + allowCredentials + "]");
|
||||
}
|
||||
|
||||
if (annotation.maxAge() >= 0 && config.getMaxAge() == null) {
|
||||
if (annotation.maxAge() >= 0) {
|
||||
config.setMaxAge(annotation.maxAge());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -29,6 +29,7 @@ import org.springframework.http.HttpMethod;
|
||||
import org.springframework.http.HttpStatus;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.http.client.HttpComponentsClientHttpRequestFactory;
|
||||
import org.springframework.stereotype.Controller;
|
||||
import org.springframework.web.bind.annotation.CrossOrigin;
|
||||
import org.springframework.web.bind.annotation.GetMapping;
|
||||
import org.springframework.web.bind.annotation.PostMapping;
|
||||
@@ -37,6 +38,7 @@ import org.springframework.web.bind.annotation.RequestMethod;
|
||||
import org.springframework.web.bind.annotation.RestController;
|
||||
import org.springframework.web.client.HttpClientErrorException;
|
||||
import org.springframework.web.client.RestTemplate;
|
||||
import org.springframework.web.cors.CorsConfiguration;
|
||||
import org.springframework.web.reactive.config.EnableWebFlux;
|
||||
import org.springframework.web.testfixture.http.server.reactive.bootstrap.HttpServer;
|
||||
|
||||
@@ -257,6 +259,19 @@ class CrossOriginAnnotationIntegrationTests extends AbstractRequestMappingIntegr
|
||||
assertThat(entity.getHeaders().getAccessControlAllowCredentials()).isTrue();
|
||||
}
|
||||
|
||||
@ParameterizedHttpServerTest
|
||||
void maxAgeWithDefaultOrigin(HttpServer httpServer) throws Exception {
|
||||
startServer(httpServer);
|
||||
|
||||
this.headers.add(HttpHeaders.ACCESS_CONTROL_REQUEST_METHOD, "GET");
|
||||
ResponseEntity<String> entity = performOptions("/classAge", this.headers, String.class);
|
||||
assertThat(entity.getStatusCode()).isEqualTo(HttpStatus.OK);
|
||||
assertThat(entity.getHeaders().getAccessControlMaxAge()).isEqualTo(10);
|
||||
|
||||
entity = performOptions("/methodAge", this.headers, String.class);
|
||||
assertThat(entity.getStatusCode()).isEqualTo(HttpStatus.OK);
|
||||
assertThat(entity.getHeaders().getAccessControlMaxAge()).isEqualTo(100);
|
||||
}
|
||||
|
||||
@Configuration
|
||||
@EnableWebFlux
|
||||
@@ -361,4 +376,21 @@ class CrossOriginAnnotationIntegrationTests extends AbstractRequestMappingIntegr
|
||||
}
|
||||
}
|
||||
|
||||
@RestController
|
||||
@CrossOrigin(maxAge = 10)
|
||||
private static class MaxAgeWithDefaultOriginController {
|
||||
|
||||
@CrossOrigin
|
||||
@GetMapping(path = "/classAge")
|
||||
public String classAge() {
|
||||
return "classAge";
|
||||
}
|
||||
|
||||
@CrossOrigin(maxAge = 100)
|
||||
@GetMapping(path = "/methodAge")
|
||||
public String methodAge() {
|
||||
return "methodAge";
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
@@ -456,7 +456,7 @@ public class RequestMappingHandlerMapping extends RequestMappingInfoHandlerMappi
|
||||
"or an empty string (\"\"): current value is [" + allowCredentials + "]");
|
||||
}
|
||||
|
||||
if (annotation.maxAge() >= 0 && config.getMaxAge() == null) {
|
||||
if (annotation.maxAge() >= 0) {
|
||||
config.setMaxAge(annotation.maxAge());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -310,6 +310,27 @@ public class CrossOriginTests {
|
||||
assertThat(this.handlerMapping.getHandler(request)).isNull();
|
||||
}
|
||||
|
||||
@Test
|
||||
public void maxAgeWithDefaultOrigin() throws Exception {
|
||||
this.handlerMapping.registerHandler(new MaxAgeWithDefaultOriginController());
|
||||
|
||||
this.request.setRequestURI("/classAge");
|
||||
HandlerExecutionChain chain = this.handlerMapping.getHandler(request);
|
||||
CorsConfiguration config = getCorsConfiguration(chain, false);
|
||||
assertThat(config).isNotNull();
|
||||
assertThat(config.getAllowedMethods()).containsExactly("GET");
|
||||
assertThat(config.getAllowedOrigins()).containsExactly("*");
|
||||
assertThat(config.getMaxAge()).isEqualTo(10);
|
||||
|
||||
this.request.setRequestURI("/methodAge");
|
||||
chain = this.handlerMapping.getHandler(request);
|
||||
config = getCorsConfiguration(chain, false);
|
||||
assertThat(config).isNotNull();
|
||||
assertThat(config.getAllowedMethods()).containsExactly("GET");
|
||||
assertThat(config.getAllowedOrigins()).containsExactly("*");
|
||||
assertThat(config.getMaxAge()).isEqualTo(100);
|
||||
}
|
||||
|
||||
|
||||
private CorsConfiguration getCorsConfiguration(HandlerExecutionChain chain, boolean isPreFlightRequest) {
|
||||
if (isPreFlightRequest) {
|
||||
@@ -425,7 +446,21 @@ public class CrossOriginTests {
|
||||
@RequestMapping(path = "/baz", method = RequestMethod.GET)
|
||||
public void baz() {
|
||||
}
|
||||
}
|
||||
|
||||
@Controller
|
||||
@CrossOrigin(maxAge = 10)
|
||||
private static class MaxAgeWithDefaultOriginController {
|
||||
|
||||
@CrossOrigin
|
||||
@RequestMapping(path = "/classAge", method = RequestMethod.GET)
|
||||
public void classAge() {
|
||||
}
|
||||
|
||||
@CrossOrigin(maxAge = 100)
|
||||
@RequestMapping(path = "/methodAge", method = RequestMethod.GET)
|
||||
public void methodAge() {
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user