Remove duplicate CorsFilter bean causing double Access-Control-Allow-Origin header

FixSecurityService
Shipped
April 25, 2026 at 10:39 PM UTC
Author
Kamo
Commit
bf57a38

The explicit CorsFilter bean caused a second CORS filter alongside Spring Security's built-in CORS support (which uses CorsConfigurationSource). Both filters resolved the origin pattern and wrote the same header, producing the duplicate 'https://www.kamocrm.com, https://www.kamocrm.com' value that browsers reject. Removing the bean leaves CorsConfigurationSource in place for Spring Security and eliminates the duplicate.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing