默认情况下,只有七种 simple response headers(简单响应首部)可以暴露给外部:
Cache-Control
Content-Language
Content-Length
Content-Type
Expires
Last-Modified
Pragma
所以,想暴露Authorization给前端 需要设置响应首部 Access-Control-Expose-Headers
public boolean preHandle(HttpServletRequest httpServletRequest,
HttpServletResponse httpServletResponse,
Object object) throws Exception{
httpServletResponse.setHeader("Access-Control-Expose-Headers","Authorization");
return true;
}