Skip to content

Commit

Permalink
fix: SecurityFilter를 거치는 POST 요청 처리를 위한 Cors 설정
Browse files Browse the repository at this point in the history
  • Loading branch information
xGreenNarae committed Nov 3, 2023
1 parent 2013d83 commit 7706441
Show file tree
Hide file tree
Showing 2 changed files with 18 additions and 20 deletions.

This file was deleted.

Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,9 @@
import org.springframework.security.config.http.SessionCreationPolicy;
import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;
import org.springframework.security.web.SecurityFilterChain;
import org.springframework.web.cors.CorsConfiguration;
import org.springframework.web.cors.CorsConfigurationSource;
import org.springframework.web.cors.UrlBasedCorsConfigurationSource;
import org.springframework.web.servlet.HandlerExceptionResolver;

import javax.servlet.http.HttpServletResponse;
Expand All @@ -32,11 +35,25 @@ public BCryptPasswordEncoder registerPasswordEncoder() {
return new BCryptPasswordEncoder();
}

@Bean
public CorsConfigurationSource configureCors() {
final CorsConfiguration configuration = new CorsConfiguration();
configuration.addAllowedHeader("*");
configuration.addAllowedMethod("*");
configuration.addAllowedOriginPattern("*");
configuration.setAllowCredentials(true);
configuration.addExposedHeader("Authorization");

final UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource();
source.registerCorsConfiguration("/**", configuration);
return source;
}

@Bean
public SecurityFilterChain securityFilterChain(final HttpSecurity http,
@Autowired @Qualifier("handlerExceptionResolver") final HandlerExceptionResolver resolver) throws Exception {
http.cors().configurationSource(configureCors());
http.csrf().disable();
http.cors();

http.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS);

Expand Down

0 comments on commit 7706441

Please sign in to comment.