解决ajax跨域请求携带cookie的问题

在springmvc中,ajax进行跨域请求时,可以使用@CrossOrigin注解就能实现跨域
但是上面适用于不传递cookie的情况,如若要传递cookie信息,前端请求时需要做出改变
	$.ajax({
			type:'post',
			url: 'http://localhost:8085/cart/selectCartShopNum',
			dataType: 'json',
			xhrFields: {
				withCredentials: true  //解决跨服务传递时不传递cookie的问题,允许携带证书
			},
			crossDomain: true,  //允许跨域
			success: function (data) {
				console.info(data)
				if (data.status == 200){
					alert(data.data)
					$("#shopping-num").html = data.data
				}
			}
		})
这时如果后台还使用@CrossOrigin前端页面会报错

The value of the ‘Access-Control-Allow-Origin’ header in the response must not be the wildcard ‘*’ when the request’s credentials mode is ‘include’.

为什么这次用注解会不好使了呢,经过百度,应该是@CrossOrigin注解和前端上面的配置有所冲突,这时需要写一个过滤器进行跨域
首先配置web.xml

    <filter>
        <filter-name>filterfilter-name>
        <filter-class>com.qiudong.cart.filter.CorsFilterfilter-class>
    filter>
    <filter-mapping>
        <filter-name>filterfilter-name>
        <url-pattern>/*url-pattern>
    filter-mapping>
过滤器代码
//解决ajax携带cookie的跨域问题,使用@CrossOrigin注解冲突
public class CorsFilter implements Filter {
    @Override
    public void init(FilterConfig filterConfig) throws ServletException {

    }

    @Override
    public void doFilter(ServletRequest req, ServletResponse res, FilterChain chain) throws IOException, ServletException {
        HttpServletResponse response = (HttpServletResponse) res;

        HttpServletRequest reqs = (HttpServletRequest) req;

        // response.setHeader("Access-Control-Allow-Origin",reqs.getHeader("Origin"));
        //注意重点:下面的第二个参数不可以写*通配,需要明确写出请求方的IP地址及端口
        response.setHeader("Access-Control-Allow-Origin","http://localhost:8081");
        response.setHeader("Access-Control-Allow-Credentials", "true");
        response.setHeader("Access-Control-Allow-Methods", "POST, GET, PATCH, DELETE, PUT");
        response.setHeader("Access-Control-Max-Age", "3600");
        response.setHeader("Access-Control-Allow-Headers", "Origin, X-Requested-With, Content-Type, Accept");
        chain.doFilter(req, res);
    }

    @Override
    public void destroy() {

    }
}

你可能感兴趣的:(bug)