Remove duplicate CorsFilter and strip upstream CORS headers in gateway

FixAPIService
Shipped
April 25, 2026 at 10:39 PM UTC
Author
Kamo
Commit
2c16fd4

WebConfig.java defined a second CorsFilter bean competing with CorsConfig.java's bean, risking duplicate header writes. Deleted it so only one CorsFilter exists. The forward() method also copied Access-Control-Allow-Origin from upstream service responses back to the browser, then the gateway's own CorsFilter added another copy — producing the duplicate header. Now all CORS headers are stripped from the upstream response before it is forwarded; the gateway's single CorsFilter writes them once.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing