8
Sorry for posting this rather large post. But I don't see a way to get it any smaller. Blame CORS :)
Versions:
- Angularjs Version: 1.1.3
- Jetty Version: 8.1.9
- Jetty Servlets Version: 8.1.9.v20130131 (Used for Jettys CrossOriginFilter)
What I want to achieve
Cross Origin Request using Basic Authorization header:
- with $http method from Angularjs originating from localhost:8000
- to localhost:8080/api/user (Spring MVC REST interface).
Issue:
- HTTPFox shows that OPTIONS request to /api/user was denied with Response 302 (NS_ERROR_DOM_BAD_URI)
- Server is responding with 302 instead of 200 if Authorization Basic header is sent.
- So called Simple CORS headers work (without Angularjs Authorization Basic header set).
- Angularjs returns 0 as status (instead of 302 or 200).
- In the Response Header of HTTPFox Location header redirects as if Authorization failed
- Tests with Curl (with Authorization Header set) work without any issues
- Supplied Base64 encoded Authorization String is correct.
Questions:
- What is the reason for OPTIONS 302 (NS_ERROR_DOM_BAD_URI)? How can I solve it?
- Why does Angularjs return 0 instead of 302 or 200 (seems an issue with x-requested-with)?
- Is using Cross Origin with browsers really a good idea for production (it seems like there are many issues)?
CORS settings in web.xml of Spring configuration:
allowedOrigins: *
allowedMethods: GET,POST,DELETE,PUT,HEAD,OPTIONS
allowedHeaders: origin,content-type,accept,authorization,x-requested-with
supportsCredentials: true
Angularjs http request (Origins from: localhost:8000):
$http.get('localhost:8080/api/user', {headers: {'Authorization':'Basic