Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Spring MVC CORS: a browser-origin policy is not authentication

Last updated: 29 Sept 20264 min read
tutorial
IntermediateBy AITrove Editorial

CORS specifies which browser origins may read or send cross-origin requests under the configured browser rules; it does not identify a user.

Download Spring source kit

This lesson uses the downloadable source kit: Java 21, Spring Boot 4.0.8 and its managed Spring Framework 7 dependencies. The version is pinned for repeatable builds.

Allow the intended origin

The kit permits https://reader.aitrove.in for receipt API requests and includes credentials. Its real HTTP preflight test checks that the allowed origin is echoed and that an unlisted origin is rejected. The origin is a fixture configuration, not evidence that this domain currently hosts a reader application.

A credentialed browser request needs a specific allowed origin policy. Broad origin patterns require an equally explicit trust decision. Do not weaken that decision merely because a development tool can send requests without browser CORS enforcement.

Filters and handlers share the request boundary

The security chain enables CORS integration so preflight can be handled before an authentication challenge defeats the browser’s request. Authentication and CSRF still govern the actual protected operation.

A non-browser client is not prevented from making an HTTP request just because its Origin header is absent. Authorization must reject the request on its own merits. CORS and bearer-token storage are separate concerns.

Checked source

Java
package in.aitrove.learning;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.servlet.config.annotation.WebMvcConfigurer;
import org.springframework.web.servlet.config.annotation.CorsRegistry;
@Configuration(proxyBeanMethods=false)
public class ReceiptWebConfig implements WebMvcConfigurer {
    public void addCorsMappings(CorsRegistry registry) {
        registry.addMapping("/api/receipts/**").allowedOrigins("https://reader.aitrove.in")
            .allowedMethods("GET", "POST").allowCredentials(true).maxAge(600);
    }
}

Test the boundary

Run mvn test in the source-kit directory. HttpSecurityBoundaryTest.configuredOriginPassesCorsPreflight and unlistedOriginIsRejected checks the behavior described here. Java excerpts belong to the named source-kit classes; they are not independent source files unless the complete class is shown.

Costs and boundaries

The preflight cache duration is six hundred seconds in this fixture. Browser caching reduces repeated preflights but can delay observation of a changed policy; do not interpret it as server authentication state.

Common Mistakes

  • CORS is not user authentication.
  • Do not infer browser behavior from a client that ignores CORS.
  • Keep CSRF and credential handling explicit.

Read next

Security filter chain, Spring MVC request validation: reject invalid commands before mutation, Java HttpClient: request policy, deadlines, and response size.

spring
spring-boot
cors-boundaries
Storage details