Logo Questions Linux Laravel Mysql Ubuntu Git Menu

How to setup Access-Control-Allow-Origin filter problematically in Spring Security 3.2

I am trying to setup my Spring server with Spring Security 3.2 to be able to do an ajax login request.

I followed the Spring Security 3.2 video and couple of posts but the issue is that I am getting

 No 'Access-Control-Allow-Origin' header is present on the requested resource. Origin '' is therefore not allowed access. 

For the login requests (see below).

I have created a CORSFilter setup and I can access the unprotected resources in my system with the appropriate headers being added to the response.

My guess is that I am not adding the CORSFilter to security filter chain or it may be too late far in the chain. Any idea will be appreciated.


public class WebAppInitializer implements WebApplicationInitializer {
    public void onStartup(ServletContext servletContext) {
        WebApplicationContext rootContext = createRootContext(servletContext);

        configureSpringMvc(servletContext, rootContext);

        FilterRegistration.Dynamic corsFilter = servletContext.addFilter("corsFilter", CORSFilter.class);
        corsFilter.addMappingForUrlPatterns(null, false, "/*");

    private WebApplicationContext createRootContext(ServletContext servletContext) {
        AnnotationConfigWebApplicationContext rootContext = new AnnotationConfigWebApplicationContext();

        rootContext.register(SecurityConfig.class, PersistenceConfig.class, CoreConfig.class);

        servletContext.addListener(new ContextLoaderListener(rootContext));
        servletContext.setInitParameter("defaultHtmlEscape", "true");

        return rootContext;

    private void configureSpringMvc(ServletContext servletContext, WebApplicationContext rootContext) {
        AnnotationConfigWebApplicationContext mvcContext = new AnnotationConfigWebApplicationContext();

        ServletRegistration.Dynamic appServlet = servletContext.addServlet(
                "webservice", new DispatcherServlet(mvcContext));
        Set<String> mappingConflicts = appServlet.addMapping("/api/*");

        if (!mappingConflicts.isEmpty()) {
            for (String s : mappingConflicts) {
                LOG.error("Mapping conflict: " + s);
            throw new IllegalStateException(
                    "'webservice' cannot be mapped to '/'");


public class SecurityWebAppInitializer extends AbstractSecurityWebApplicationInitializer {


Requests to /api/users - work well and the Access-Control-Allow headers are added . I disabled csrf and headers just to make sure this is not the case

public class SecurityConfig extends WebSecurityConfigurerAdapter {

    protected void registerAuthentication(AuthenticationManagerBuilder auth) throws Exception {

    protected void configure(HttpSecurity http) throws Exception {


public class CORSFilter implements Filter{
    static Logger logger = LoggerFactory.getLogger(CORSFilter.class);

    public void init(FilterConfig filterConfig) throws ServletException {

    public void doFilter(ServletRequest request, ServletResponse res, FilterChain chain) throws IOException, ServletException {
        HttpServletResponse response = (HttpServletResponse) res;
        response.setHeader("Access-Control-Allow-Origin", "*");
        response.setHeader("Access-Control-Allow-Methods", "POST, GET, OPTIONS, DELETE");
        response.setHeader("Access-Control-Max-Age", "3600");
        response.setHeader("Access-Control-Allow-Headers", "x-requested-with");
        chain.doFilter(request, response);

    public void destroy() {}

Login Request:

Request URL:http://localhost:8080/devstage-1.0/login
Request Headers CAUTION: Provisional headers are shown.
Accept:application/json, text/plain, */*
User-Agent:Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.154 Safari/537.36
Form Dataview sourceview URL encoded
like image 965
special0ne Avatar asked Apr 05 '14 20:04


People also ask

How do I enable CORS in Spring Security?

Enabling CORS Configuration Globally in Spring Webflux To define CORS globally in a Spring Webflux application, we use the WebfluxConfigurer and override the addCorsMappings() . Similar to Spring MVC, it uses a CorsConfiguration with defaults that can be overridden as required.

How do I add Access-Control allow Origin header in spring boot?

You can add @CrossOrigin("http://localhost:8080") to proper method if you want :8080 to allow request there. It's a simple config for one endpoint/controller. You can use variable there too for customization later of course.

1 Answers

All I was missing was AddFilterBefore when configuring the security configuration.

So the final version was:

public class SecurityConfig extends WebSecurityConfigurerAdapter {

  protected void registerAuthentication(AuthenticationManagerBuilder auth) throws Exception {

  protected void configure(HttpSecurity http) throws Exception {
          .addFilterBefore(new CORSFilter(), ChannelProcessingFilter.class)


And remove the CORSFilter from WebAppInitializer

like image 183
special0ne Avatar answered Oct 10 '22 17:10
