KamoCRM

Remove duplicate CorsFilter and strip upstream CORS headers in gateway

FixAPIService
Shipped
25 ஏப்ரல், 2026 அன்று 10:39 PM UTC
Author
Kamo
Commit
2c16fd4

WebConfig.java defined a second CorsFilter bean competing with CorsConfig.java's bean, risking duplicate header writes. Deleted it so only one CorsFilter exists. The forward() method also copied Access-Control-Allow-Origin from upstream service responses back to the browser, then the gateway's own CorsFilter added another copy — producing the duplicate header. Now all CORS headers are stripped from the upstream response before it is forwarded; the gateway's single CorsFilter writes them once.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing