Have you implemented OpenMRS? Please participate in the Implementation Site Survey. If you already have, thank you!
Child pages
  • OAuth2 Module - add support for CORS
Skip to end of metadata
Go to start of metadata

To enable CORS in-order to make Cross-Origin requests to REST controller, authorization or token endpoints or add custom headers to incoming requests, make the following changes.

 

Add a Tomcat CORS filter in /omod/src/main/java/resources/config.xml

<filter>
    <filter-name>CorsFilter</filter-name>
    <filter-class>org.apache.catalina.filters.CorsFilter</filter-class>
</filter>
<filter-mapping>
    <filter-name>CorsFilter</filter-name>
    <url-pattern>/*</url-pattern>
</filter-mapping>


OPTIONALLY

 

Add a custom CORS filter in /omod/src/main/java/resources/config.xml

<filter>
    <filter-name>CORSFilter</filter-name>
    <filter-class>org.openmrs.module.oauth2.web.CORSFilter</filter-class>
</filter>
<filter-mapping>
    <filter-name>CORSFilter</filter-name>
    <url-pattern>/*</url-pattern>
</filter-mapping>

And make desired changes in /omod/src/main/java/org/openmrs/module/oauth2/CORSFilter.java

 package org.openmrs.module.oauth2.web;

import org.springframework.web.filter.OncePerRequestFilter;

import javax.servlet.FilterChain;
import javax.servlet.ServletException;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;
/*
* Custom CORS filter
* To use this declare filter mapping in config.xml
 */
public class CORSFilter extends OncePerRequestFilter{

   @Override
   protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response,
         FilterChain filterChain) throws ServletException, IOException {
      if(request.getHeader("Access-Control-Request-Method") != null && "OPTIONS".equals(request.getMethod())) {
         // CORS "pre-flight" request
         response.addHeader("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE");
         response.addHeader("Access-Control-Allow-Headers", "Authorization");
         response.addHeader("Access-Control-Allow-Headers", "Content-Type");
         response.addHeader("Access-Control-Allow-Origin","*");
         response.addHeader("Access-Control-Max-Age", "1");
      }

      filterChain.doFilter(request, response);
   }
}


 

 

  • No labels