001/* 002 * Copyright 2002-2017 the original author or authors. 003 * 004 * Licensed under the Apache License, Version 2.0 (the "License"); 005 * you may not use this file except in compliance with the License. 006 * You may obtain a copy of the License at 007 * 008 * https://www.apache.org/licenses/LICENSE-2.0 009 * 010 * Unless required by applicable law or agreed to in writing, software 011 * distributed under the License is distributed on an "AS IS" BASIS, 012 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 013 * See the License for the specific language governing permissions and 014 * limitations under the License. 015 */ 016 017package org.springframework.web.cors.reactive; 018 019import org.springframework.lang.Nullable; 020import org.springframework.web.cors.CorsConfiguration; 021import org.springframework.web.server.ServerWebExchange; 022 023/** 024 * A strategy to apply CORS validation checks and updates to a 025 * {@link ServerWebExchange}, either rejecting through the response or adding 026 * CORS related headers, based on a pre-selected {@link CorsConfiguration}. 027 * 028 * @author Sebastien Deleuze 029 * @author Rossen Stoyanchev 030 * @since 5.0 031 * @see <a href="https://www.w3.org/TR/cors/">CORS W3C recommendation</a> 032 */ 033public interface CorsProcessor { 034 035 /** 036 * Process a request using the given {@code CorsConfiguration}. 037 * @param configuration the CORS configuration to use; possibly {@code null} 038 * in which case pre-flight requests are rejected, but all others allowed. 039 * @param exchange the current exchange 040 * @return {@code false} if the request was rejected, {@code true} otherwise 041 */ 042 boolean process(@Nullable CorsConfiguration configuration, ServerWebExchange exchange); 043 044}