KamoCRM

Remove duplicate CorsFilter bean causing double Access-Control-Allow-Origin header

FixSecurityService
Shipped
25 ஏப்ரல், 2026 அன்று 10:39 PM UTC
Author
Kamo
Commit
bf57a38

The explicit CorsFilter bean caused a second CORS filter alongside Spring Security's built-in CORS support (which uses CorsConfigurationSource). Both filters resolved the origin pattern and wrote the same header, producing the duplicate 'https://www.kamocrm.com, https://www.kamocrm.com' value that browsers reject. Removing the bean leaves CorsConfigurationSource in place for Spring Security and eliminates the duplicate.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing