Ensure local @CrossOrigin maxAge overrides global value

Prior to this commit, a method-level @CrossOrigin maxAge value did not
override a class-level @CrossOrigin maxAge value. This contradicts the
Javadoc for @CrossOrgin which states the following.

    For those attributes where only a single value can be accepted such
    as allowCredentials and maxAge, the local overrides the global
    value.

This commit ensures that a method-level @CrossOrigin maxAge value
overrides a class-level @CrossOrigin maxAge value.

Closes gh-26619
This commit is contained in:
GungnirLaevatain
2021-02-27 17:44:02 +08:00
committed by Sam Brannen
parent 428dbc43da
commit e8f685ecc8
4 changed files with 69 additions and 2 deletions

View File

@@ -338,7 +338,7 @@ public class RequestMappingHandlerMapping extends RequestMappingInfoHandlerMappi
"or an empty string (\"\"): current value is [" + allowCredentials + "]");
}
if (annotation.maxAge() >= 0 && config.getMaxAge() == null) {
if (annotation.maxAge() >= 0) {
config.setMaxAge(annotation.maxAge());
}
}

View File

@@ -29,6 +29,7 @@ import org.springframework.http.HttpMethod;
import org.springframework.http.HttpStatus;
import org.springframework.http.ResponseEntity;
import org.springframework.http.client.HttpComponentsClientHttpRequestFactory;
import org.springframework.stereotype.Controller;
import org.springframework.web.bind.annotation.CrossOrigin;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.PostMapping;
@@ -37,6 +38,7 @@ import org.springframework.web.bind.annotation.RequestMethod;
import org.springframework.web.bind.annotation.RestController;
import org.springframework.web.client.HttpClientErrorException;
import org.springframework.web.client.RestTemplate;
import org.springframework.web.cors.CorsConfiguration;
import org.springframework.web.reactive.config.EnableWebFlux;
import org.springframework.web.testfixture.http.server.reactive.bootstrap.HttpServer;
@@ -257,6 +259,19 @@ class CrossOriginAnnotationIntegrationTests extends AbstractRequestMappingIntegr
assertThat(entity.getHeaders().getAccessControlAllowCredentials()).isTrue();
}
@ParameterizedHttpServerTest
void maxAgeWithDefaultOrigin(HttpServer httpServer) throws Exception {
startServer(httpServer);
this.headers.add(HttpHeaders.ACCESS_CONTROL_REQUEST_METHOD, "GET");
ResponseEntity<String> entity = performOptions("/classAge", this.headers, String.class);
assertThat(entity.getStatusCode()).isEqualTo(HttpStatus.OK);
assertThat(entity.getHeaders().getAccessControlMaxAge()).isEqualTo(10);
entity = performOptions("/methodAge", this.headers, String.class);
assertThat(entity.getStatusCode()).isEqualTo(HttpStatus.OK);
assertThat(entity.getHeaders().getAccessControlMaxAge()).isEqualTo(100);
}
@Configuration
@EnableWebFlux
@@ -361,4 +376,21 @@ class CrossOriginAnnotationIntegrationTests extends AbstractRequestMappingIntegr
}
}
@RestController
@CrossOrigin(maxAge = 10)
private static class MaxAgeWithDefaultOriginController {
@CrossOrigin
@GetMapping(path = "/classAge")
public String classAge() {
return "classAge";
}
@CrossOrigin(maxAge = 100)
@GetMapping(path = "/methodAge")
public String methodAge() {
return "methodAge";
}
}
}