OAuth2 Module - add support for CORS

To enable CORS in-order to make Cross-Origin requests to REST controller, authorization or token endpoints or add custom headers to incoming requests, make the following changes.

 

Add a Tomcat CORS filter in /omod/src/main/java/resources/config.xml

<filter> <filter-name>CorsFilter</filter-name> <filter-class>org.apache.catalina.filters.CorsFilter</filter-class> </filter> <filter-mapping> <filter-name>CorsFilter</filter-name> <url-pattern>/*</url-pattern> </filter-mapping>



OPTIONALLY

 

Add a custom CORS filter in /omod/src/main/java/resources/config.xml

<filter> <filter-name>CORSFilter</filter-name> <filter-class>org.openmrs.module.oauth2.web.CORSFilter</filter-class> </filter> <filter-mapping> <filter-name>CORSFilter</filter-name> <url-pattern>/*</url-pattern> </filter-mapping>

And make desired changes in /omod/src/main/java/org/openmrs/module/oauth2/CORSFilter.java

 package org.openmrs.module.oauth2.web; import org.springframework.web.filter.OncePerRequestFilter; import javax.servlet.FilterChain; import javax.servlet.ServletException; import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletResponse; import java.io.IOException; /* * Custom CORS filter * To use this declare filter mapping in config.xml */ public class CORSFilter extends OncePerRequestFilter{ @Override protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain filterChain) throws ServletException, IOException { if(request.getHeader("Access-Control-Request-Method") != null && "OPTIONS".equals(request.getMethod())) { // CORS "pre-flight" request response.addHeader("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE"); response.addHeader("Access-Control-Allow-Headers", "Authorization"); response.addHeader("Access-Control-Allow-Headers", "Content-Type"); response.addHeader("Access-Control-Allow-Origin","*"); response.addHeader("Access-Control-Max-Age", "1"); } filterChain.doFilter(request, response); } }