Created
July 27, 2021 20:44
-
-
Save marcosbarker/acf54e704eb6ba59ca97a397a672d45e to your computer and use it in GitHub Desktop.
SPRING BOOT: Tratamento de CORS
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
package com.<...>.config; | |
import java.util.Arrays; | |
import org.springframework.beans.factory.annotation.Autowired; | |
import org.springframework.context.annotation.Bean; | |
import org.springframework.context.annotation.Configuration; | |
import org.springframework.core.env.Environment; | |
import org.springframework.security.config.annotation.web.builders.HttpSecurity; | |
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; | |
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; | |
import org.springframework.security.config.http.SessionCreationPolicy; | |
import org.springframework.web.cors.CorsConfiguration; | |
import org.springframework.web.cors.CorsConfigurationSource; | |
import org.springframework.web.cors.UrlBasedCorsConfigurationSource; | |
@Configuration | |
@EnableWebSecurity | |
public class SecurityConfig extends WebSecurityConfigurerAdapter { | |
@Autowired | |
private Environment env; | |
@Override | |
protected void configure(HttpSecurity http) throws Exception { | |
if (Arrays.asList(env.getActiveProfiles()).contains("test")) { | |
http.headers().frameOptions().disable(); | |
} | |
http.cors().and().csrf().disable(); | |
http.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS); | |
http.authorizeRequests().anyRequest().permitAll(); | |
} | |
@Bean | |
CorsConfigurationSource corsConfigurationSource() { | |
CorsConfiguration configuration = new CorsConfiguration().applyPermitDefaultValues(); | |
configuration.setAllowedMethods(Arrays.asList("POST", "GET", "PUT", "DELETE", "OPTIONS")); | |
final UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource(); | |
source.registerCorsConfiguration("/**", configuration); | |
return source; | |
} | |
} |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment