TODO未完成
http://pingguohe.net/2016/03/21/ajax-solution-spring.html
http://www.cnblogs.com/Darren_code/p/cors.html
http://www.ruanyifeng.com/blog/2016/04/same-origin-policy.html
http://frontenddev.org/article/ajax-browser-cross-domain-request-access-control.html