spring-projects / spring-projects/spring-security

SEC-3025: CORS: Add SpringMvcRequestMatchers.mvcPreFlightRequest

Open
#3,236 1 comment 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

in: web type: enhancement type: jira
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Rob Winch (Migrated from SEC-3025) said:

This should simply delegate to CorsUtils.isPreFlightRequest to allow preflight requests to pass through (permitAll). We keep this distinct to ensure that it is only used in Spring MVC which places certain guarantees that if CorsUtils.isPreFlightRequest returns true that no user code is executed.

It may be good to do a check to see if CrossOrigin is on the classpath since this is only intended to be used with MVC (which places certain guarantees that user code isn't executed). This also ensures that 4.2+ is being used.

This would be used with something like:

http
   .authorizeRequests()
       .matchers(mvcPreFlightRequest()).permitAll()
       ...

NOTE: We probably need to think about XML configuration...perhaps it is due time we introduce a mechanism for referring to a request matcher instance in intercept-url

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the Spring MVC request matcher entry points and the existing CorsUtils.isPreFlightRequest usage. Confirm how mvcPreFlightRequest() should permit preflight requests without invoking user code, and determine whether XML configuration is in scope; done means the matcher is available for the shown authorizeRequests() usage with appropriate coverage.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.