天天看点

java前后端分离解决跨域的问题

        最近项目有原来的jsp转为vue方式,采取的前后端分离的方式,对接过程中出现了跨域的问题,我本想让前端解决下,或者直接让他用jsonp请求,后来考虑到jsonp只能用get的方式,我这边接口的限制是post请求,于是我就在项目中添加了拦截器进行了处理。

在springmvc项目采用的是cors的模式

1、增加fileter 
@Component
public class myCORSFilter implements Filter {

    @Override
    public void init(FilterConfig filterConfig) throws ServletException {

    }

    @Override
    public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException {
        HttpServletResponse response = (HttpServletResponse) servletResponse;
        String origin = (String) servletRequest.getRemoteHost()+":"+servletRequest.getRemotePort();
        response.setHeader("Access-Control-Allow-Origin", "*");
        response.setHeader("Access-Control-Allow-Methods", "POST, GET, OPTIONS, DELETE");
        response.setHeader("Access-Control-Max-Age", "3600");
        response.setHeader("Access-Control-Allow-Headers", "x-requested-with,Authorization");
        response.setHeader("Access-Control-Allow-Credentials","true");
        filterChain.doFilter(servletRequest, servletResponse);
    }

    @Override
    public void destroy() {

    }
}
           

2、需要在web.xml中增加

<filter>
    <filter-name>cors</filter-name>
    <filter-class>com.xx.os.common.intercepter.myCORSFilter</filter-class>
</filter>
<filter-mapping>
    <filter-name>cors</filter-name>
    <url-pattern>/api/*</url-pattern>
</filter-mapping>
           

就可以解决跨域问题了

二、在springboot中添加这个就可以轻松解决了

@Configuration
public class GlobalCorsConfig {
    @Bean
    public WebMvcConfigurer corsConfigurer() {
        return new WebMvcConfigurer() {
            @Override
            //重写父类提供的跨域请求处理的接口
            public void addCorsMappings(CorsRegistry registry) {
                //添加映射路径
                registry.addMapping("/**")
                        //放行哪些原始域
                        .allowedOrigins("*")
                        //是否发送Cookie信息
                        .allowCredentials(true)
                        //放行哪些原始域(请求方式)
                        .allowedMethods("GET","POST", "PUT", "DELETE")
                        //放行哪些原始域(头部信息)
                        .allowedHeaders("*");
//                        //暴露哪些头部信息(因为跨域访问默认不能获取全部头部信息)
//                        .exposedHeaders("Header1", "Header2");
            }
        };
    }

}
           

当然在nginx里面也可以添加请求头,但是我不太喜欢用那种方式,在这就不推荐大家了