Spring Framework 7.1 removes HandlerMappingIntrospector-derived implicit
CORS handling for plain (non-preflight) requests; per spring-framework#36481,
relying on it for a plain request's CORS headers was "never an intended way
of using HandlerMappingIntrospector" and won't be reinstated.
PreFlightRequestFilter, its replacement, is a no-op for non-preflight
requests.
The following tests assert the old, implicit behavior and have been disabled
accordingly:
CorsConfigurerTests#getWhenCrossOriginAnnotationThenRespondsWithCorsHeaders
CorsConfigurerTests#getWhenDefaultsInLambdaAndCrossOriginAnnotationThenRespondsWithCorsHeaders
HttpCorsConfigTests#getWhenUsingCorsThenDoesSpringSecurityCorsHandshake
The team should confirm whether to update their expectations (e.g. require
an explicit CorsConfigurationSource bean, matching the reactive stack's
always-explicit model) or remove them outright.
Related to #19528.
Spring Framework 7.1 removes
HandlerMappingIntrospector-derived implicitCORS handling for plain (non-preflight) requests; per spring-framework#36481,
relying on it for a plain request's CORS headers was "never an intended way
of using
HandlerMappingIntrospector" and won't be reinstated.PreFlightRequestFilter, its replacement, is a no-op for non-preflightrequests.
The following tests assert the old, implicit behavior and have been disabled
accordingly:
CorsConfigurerTests#getWhenCrossOriginAnnotationThenRespondsWithCorsHeadersCorsConfigurerTests#getWhenDefaultsInLambdaAndCrossOriginAnnotationThenRespondsWithCorsHeadersHttpCorsConfigTests#getWhenUsingCorsThenDoesSpringSecurityCorsHandshakeThe team should confirm whether to update their expectations (e.g. require
an explicit
CorsConfigurationSourcebean, matching the reactive stack'salways-explicit model) or remove them outright.
Related to #19528.