Skip to content

Disable CORS Tests Relying on HandlerMappingIntrospector #19543

Description

@jzheaux

Spring Framework 7.1 removes HandlerMappingIntrospector-derived implicit
CORS handling for plain (non-preflight) requests; per spring-framework#36481,
relying on it for a plain request's CORS headers was "never an intended way
of using HandlerMappingIntrospector" and won't be reinstated.
PreFlightRequestFilter, its replacement, is a no-op for non-preflight
requests.

The following tests assert the old, implicit behavior and have been disabled
accordingly:

  • CorsConfigurerTests#getWhenCrossOriginAnnotationThenRespondsWithCorsHeaders
  • CorsConfigurerTests#getWhenDefaultsInLambdaAndCrossOriginAnnotationThenRespondsWithCorsHeaders
  • HttpCorsConfigTests#getWhenUsingCorsThenDoesSpringSecurityCorsHandshake

The team should confirm whether to update their expectations (e.g. require
an explicit CorsConfigurationSource bean, matching the reactive stack's
always-explicit model) or remove them outright.

Related to #19528.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

in: configAn issue in spring-security-configtype: taskA general task

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions