@@ -50,7 +50,7 @@ protected void configure(HttpSecurity http) throws Exception {
50
50
.logoutSuccessHandler (logoutSuccessHandler )
51
51
.and ()
52
52
.authorizeRequests ()
53
- .antMatchers ( "/api/unauthorized" , "/api/signup" , "/api/login" ).permitAll ()
53
+ .antMatchers ( "/api/unauthorized" , "/api/signup" , "/api/login" , "/api/toppost" ).permitAll ()
54
54
.antMatchers (HttpMethod .OPTIONS , "/**" ).permitAll ()
55
55
.anyRequest ().authenticated ()
56
56
.and ().cors (Customizer .withDefaults ());
@@ -61,11 +61,12 @@ CorsConfigurationSource corsConfigurationSource() {
61
61
CorsConfiguration configuration = new CorsConfiguration ();
62
62
configuration .setAllowedOrigins (Arrays .asList ("*" ));
63
63
configuration .setAllowedMethods (Arrays .asList ("GET" ,"POST" , "OPTIONS" , "PUT" , "DELETE" ));
64
- configuration .setAllowedHeaders (Arrays .asList ("X-Requested-With" , "Origin" , "Content-Type" , "Accept" ,
65
- "Authorization" , "Access-Control-Allow-Credentials" , "Access-Control-Allow-Headers" , "Access-Control-Allow-Methods" ,
66
- "Access-Control-Allow-Origin" , "Access-Control-Expose-Headers" , "Access-Control-Max-Age" ,
67
- "Access-Control-Request-Headers" , "Access-Control-Request-Method" , "Age" , "Allow" , "Alternates" ,
68
- "Content-Range" , "Content-Disposition" , "Content-Description" ));
64
+ // configuration.setAllowedHeaders(Arrays.asList("X-Requested-With", "Origin", "Content-Type", "Accept",
65
+ // "Authorization", "Access-Control-Allow-Credentials", "Access-Control-Allow-Headers", "Access-Control-Allow-Methods",
66
+ // "Access-Control-Allow-Origin", "Access-Control-Expose-Headers", "Access-Control-Max-Age",
67
+ // "Access-Control-Request-Headers", "Access-Control-Request-Method", "Age", "Allow", "Alternates",
68
+ // "Content-Range", "Content-Disposition", "Content-Description"));
69
+ configuration .setAllowedHeaders (Arrays .asList ("*" ));
69
70
configuration .setAllowCredentials (true );
70
71
UrlBasedCorsConfigurationSource source = new UrlBasedCorsConfigurationSource ();
71
72
source .registerCorsConfiguration ("/**" , configuration );
0 commit comments