Spring Boot upgrade, set-cooike header not passed from ResponseEntity

Viewed 348

I'm trying to upgrade Spring Boot from 1.3.8.RELEASE to 1.4.0.RELEASE after the upgrade, the Set-Cookie headers are NOT passed to the browser

@RequestMapping(method = RequestMethod.POST)
public HttpEntity<Result> postRequest( @RequestBody RequestObject r ){
    Result body = getBody(r);
    HttpHeader header = getHeader(); //contains Set-Cookie
    return new ResponseEntity(body,header,Httpstatus.OK)
}

I read around I found this alternative solution which works but requires me to change the controller:

@RequestMapping(method = RequestMethod.POST)
public HttpEntity<Result> postRequest( @RequestBody RequestObject r, HttpServletResponse httpResponse ){
    Result body = getBody(r);
    HttpHeader header = getHeader(); //contains Set-Cookie foo=bar
    response.addCookie(new Cookie("foo", "bar"));
    return new ResponseEntity(body,header,Httpstatus.OK)
}

However, there are many many controllers and I don't like to change every single one. Is there a new Security Feature in the newer Spring Boot that I'm not aware of so I could turn off/on to make the old code work throughout the project?

I really don't want to change over 500 controllers...

NOTE: Other Headers that are not Set-Cookie get passed through.

1 Answers

You could try adding your "set-cookie" header to the list of exposed headers, which should be accessible by the browser.

Example-

HttpHeaders responseHeaders = new HttpHeaders();
responseHeaders.setHeader({your header name}, {value of header}); //set your header

//add the header names you want to expose to a list 
List<String> allowedHeaders = new ArrayList<>();
allowedHeaders.add({your header name});           

//add the list of headers to be exposed to the Access-Control-Expose-Headers header
responseHeaders.put("Access-Control-Expose-Headers", allowedHeaders);  
Related