1. 程式人生 > 其它 >Springboot+shiro的跨域處理,親測有用

Springboot+shiro的跨域處理,親測有用

一、在config包(一般與Controller,service,pojo等同級)下建立CORSFilter繼承import org.apache.shiro.web.servlet.OncePerRequestFilter。這裡面所有的放行不能用*必須得是具體的值,不然是無法跨域成功滴。

@Component
@Configuration
//解決Access-Control-Allow-Origin跨域問題
class CORSFilter extends OncePerRequestFilter {
    public void doFilterInternal(ServletRequest req, ServletResponse res, FilterChain chain) throws
IOException, ServletException { HttpServletResponse response = (HttpServletResponse) res; HttpServletRequest request = (HttpServletRequest) req; response.setContentType("text/html;charset=UTF-8"); res.setContentType("text/html;charset=UTF-8"); response.setHeader(
"XDomainRequestAllowed","1");//不可以放在後面 //放行所有,類似*,這裡的*完全無效 response.setHeader("Access-Control-Allow-Origin", request.getHeader("origin")); response.setHeader("Access-Control-Allow-Credentials", "true"); //允許請求方式 response.setHeader("Access-Control-Allow-Methods", "POST,PUT, GET, OPTIONS, DELETE"); response.setHeader(
"Access-Control-Max-Age", "3600"); //需要放行header頭部欄位 如需鑑權欄位,自行新增,如Authorization等 response.setHeader("Access-Control-Allow-Headers", "content-type,x-requested-with,Authorization," + "authorization,Origin,No-Cache,X-Requested-With,If-Modified-Since," + " Pragma, Last-Modified, Cache-Control,Expires, Content-Type, X-E4M-With,userId,token"); response.setCharacterEncoding("UTF-8"); response.setContentType("application/json");      //請求預檢放行--不能省 if ("OPTIONS".equals(request.getMethod())) { response.setStatus(HttpStatus.NO_CONTENT.value()); return ; } else { chain.doFilter(request, response); } } }

二、在shiro的配置類ShiroConfig(裡面配置了放行哪些資源,訪問哪些需要什麼許可權等的配置類)裡面新增如下程式碼,不要忘記加註解@Bean

    @Bean
    public FilterRegistrationBean replaceTokenFilter(){
        FilterRegistrationBean registration = new FilterRegistrationBean();
        registration.setDispatcherTypes(DispatcherType.REQUEST);
        registration.setFilter( new CORSFilter());
        registration.addUrlPatterns("/*");
        registration.setName("CrosFilter");
        registration.setOrder(1);
        return registration;
    }

三、輸入網址測試,然後就可以看到正常跨域訪問介面了,如果跨域不成功的話頁面是一片空白報錯Access-Control-Allow-Origin或者Access-Control-Allow-Headers等資訊