3
votes

I am using Spring 5 Webflux with Basic Authentication.

Problem:
When I type a wrong username or password spring reponses with Http Status 401 and includes the www-authenticate: Basic realm="Realm" Http Header which causes the browser to pop up the basic auth box.

How to remove that HTTP Header in Spring 5 Webflux?
Do I have to do a custom Webfilter?

2

2 Answers

1
votes

The code below is in Kotlin copied from my project. But the idea can be simply transfered into Java.

So the solution is tied around a custom Webfilter.

@Component
class HttpHeaderWebFilter: WebFilter {

    override fun filter(exchange: ServerWebExchange, next: WebFilterChain): Mono<Void> {

        return next.filter(exchange).then(Mono.defer {

            val headers = exchange.response.headers

            if (headers.containsKey("WWW-Authenticate")) {
                headers.remove("WWW-Authenticate")
            }

            Mono.empty<Void>()
        })
    }
}
0
votes

We can use the following

if (exchange.getRequest().getHeaders().containsKey("headerKey")) {
    exchange.getRequest().mutate().header("headerKey", null, null);
}

We are using the double null, to overcome deprecated Overriding method.

If you are using Spring Framework 5.2, usage of single null is sufficient.