Sorry for posting this rather large post. But I don't see a way to get it any smaller. Blame CORS :)

Versions:

  • Angularjs Version: 1.1.3
  • Jetty Version: 8.1.9
  • Jetty Servlets Version: 8.1.9.v20130131 (Used for Jettys CrossOriginFilter)

What I want to achieve

Cross Origin Request using Basic Authorization header:

  • with $http method from Angularjs originating from localhost:8000
  • to localhost:8080/api/user (Spring MVC REST interface).

Issue:

  • HTTPFox shows that OPTIONS request to /api/user was denied with Response 302 (NS_ERROR_DOM_BAD_URI)
  • Server is responding with 302 instead of 200 if Authorization Basic header is sent.
  • So called Simple CORS headers work (without Angularjs Authorization Basic header set).
  • Angularjs returns 0 as status (instead of 302 or 200).
  • In the Response Header of HTTPFox Location header redirects as if Authorization failed
  • Tests with Curl (with Authorization Header set) work without any issues
  • Supplied Base64 encoded Authorization String is correct.

Questions:

  • What is the reason for OPTIONS 302 (NS_ERROR_DOM_BAD_URI)? How can I solve it?
  • Why does Angularjs return 0 instead of 302 or 200 (seems an issue with x-requested-with)?
  • Is using Cross Origin with browsers really a good idea for production (it seems like there are many issues)?

CORS settings in web.xml of Spring configuration:

allowedOrigins: *
allowedMethods: GET,POST,DELETE,PUT,HEAD,OPTIONS
allowedHeaders: origin,content-type,accept,authorization,x-requested-with
supportsCredentials: true

Angularjs http request (Origins from: localhost:8000):

$http.get('localhost:8080/api/user', {headers: {'Authorization':'Basic
Edit
Report