Browse Source

Merge branch '6.4.x' into 6.5.x

pull/18141/head
Rob Winch 1 month ago
parent
commit
8fa2fc0e1e
No known key found for this signature in database
  1. 9
      docs/modules/ROOT/pages/reactive/integrations/cors.adoc
  2. 8
      docs/modules/ROOT/pages/servlet/integrations/cors.adoc

9
docs/modules/ROOT/pages/reactive/integrations/cors.adoc

@ -1,4 +1,3 @@
[[webflux-cors]] [[webflux-cors]]
= CORS = CORS
@ -75,3 +74,11 @@ fun springSecurityFilterChain(http: ServerHttpSecurity): SecurityWebFilterChain
} }
---- ----
====== ======
[WARNING]
====
CORS is a browser-based security feature.
By disabling CORS in Spring Security, you are not removing CORS protection from your browser.
Instead, you are removing CORS support from Spring Security, and users will not be able to interact with your Spring backend from a cross-origin browser application.
To fix CORS errors in your application, you must enable CORS support, and provide an appropriate configuration source.
====

8
docs/modules/ROOT/pages/servlet/integrations/cors.adoc

@ -183,3 +183,11 @@ fun corsConfigurationSource(): UrlBasedCorsConfigurationSource {
} }
---- ----
====== ======
[WARNING]
====
CORS is a browser-based security feature.
By disabling CORS in Spring Security with `.cors(CorsConfigurer::disable)`, you are not removing CORS protection from your browser.
Instead, you are removing CORS support from Spring Security, and users will not be able to interact with your Spring backend from a cross-origin browser application.
To fix CORS errors in your application, you must enable CORS support, and provide an appropriate configuration source.
====

Loading…
Cancel
Save