|
@@ -33,24 +33,16 @@ public class SessionFilter implements Filter {
|
|
|
|
|
|
@Override
|
|
@Override
|
|
public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain chain) throws IOException, ServletException {
|
|
public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain chain) throws IOException, ServletException {
|
|
- HttpServletResponse httpServletResponse = (HttpServletResponse)servletResponse;
|
|
|
|
|
|
+ HttpServletResponse response = (HttpServletResponse)servletResponse;
|
|
HttpServletRequest request = (HttpServletRequest)servletRequest;
|
|
HttpServletRequest request = (HttpServletRequest)servletRequest;
|
|
|
|
+ response.setHeader("Access-Control-Allow-Origin", "*");
|
|
|
|
+ response.setHeader("Access-Control-Allow-Methods", "POST, GET, OPTIONS, DELETE");
|
|
|
|
+ response.setHeader("Access-Control-Max-Age", "3600");
|
|
|
|
+ response.setHeader("Access-Control-Allow-Credentials", "true");
|
|
|
|
+ response.setHeader("Access-Control-Allow-Headers", "x-requested-with,Authorization,token, content-type");
|
|
if(request.getMethod().toUpperCase().equals(RestRequest.Method.OPTIONS.name())){
|
|
if(request.getMethod().toUpperCase().equals(RestRequest.Method.OPTIONS.name())){
|
|
return;
|
|
return;
|
|
}
|
|
}
|
|
- String origin = request.getHeader("Origin");
|
|
|
|
- if(origin == null) {
|
|
|
|
- origin = request.getHeader("Referer");
|
|
|
|
- }
|
|
|
|
- // 允许指定域访问跨域资源(这里不能写*,*代表接受所有域名访问,如写*则下面一行代码无效。谨记)
|
|
|
|
- httpServletResponse.setHeader("Access-Control-Allow-Origin", origin);
|
|
|
|
-// //true代表允许客户端携带cookie(此时origin值不能为“*”,只能为指定单一域名)
|
|
|
|
-// httpServletResponse.setHeader("Access-Control-Allow-Credentials", "true");
|
|
|
|
-// /// 允许浏览器在预检请求成功之后发送的实际请求方法名
|
|
|
|
-// httpServletResponse.setHeader("Access-Control-Allow-Methods", "GET, HEAD, POST, PUT, DELETE, TRACE, OPTIONS, PATCH");
|
|
|
|
-// // 允许浏览器发送的请求消息头
|
|
|
|
-// httpServletResponse.setHeader("Access-Control-Allow-Headers", "Authorization,Origin, X-Requested-With, Content-Type, Accept,Access-Token");
|
|
|
|
-
|
|
|
|
String path = request.getRequestURI().substring(request.getContextPath().length()).replaceAll("[/]+$", "");
|
|
String path = request.getRequestURI().substring(request.getContextPath().length()).replaceAll("[/]+$", "");
|
|
boolean allowedPath = ALLOWED_PATHS.contains(path);
|
|
boolean allowedPath = ALLOWED_PATHS.contains(path);
|
|
if (!allowedPath){
|
|
if (!allowedPath){
|