You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Axum框架下Cookie无法传递到同域其他路径的问题排查

问题分析与解决方案

核心原因:Cookie的默认路径限制

你遇到的问题根源在于Cookie默认会绑定到设置它的请求路径。比如你在/api/user/login接口设置Cookie时,浏览器会自动将该Cookie的Path属性设为/api/user/,这就导致只有/api/user/*前缀的路由请求会携带这个Cookie,其他路径(如/api/file/upload)不会触发Cookie的传递。

解决步骤

在构建Cookie时显式指定Path为"/",让Cookie作用于同域下的所有路径:

修改你的代码,在Cookie::build的链式调用中添加.path("/")即可:

pub fn token_to_header(&self, token: String) -> AppendHeaders<[(HeaderName, std::string::String); 1]> {
    let auth_cookie = Cookie::build("Authorization", format!("Bearer {}", token))
        .same_site(SameSite::Strict)
        .max_age(cookie::time::Duration::seconds(self.ttl))
        .secure(true)
        .http_only(true)
        .path("/") // 新增该行,指定Cookie作用于根路径
        .finish();

    return AppendHeaders([
        (SET_COOKIE, auth_cookie.stripped().to_string())
    ]);
}

额外排查点:跨域场景的CORS配置

如果你的前端和后端属于跨域场景(比如前端运行在localhost:3000,后端在localhost:8000),即便设置了Path,浏览器也不会主动携带Cookie,这时需要补充两项配置:

  • 后端在axum的CORS中间件中开启凭证允许:设置.allow_credentials(true)
  • 前端发起请求时配置携带凭证(比如fetch添加credentials: 'include',axios设置withCredentials: true)

不过你明确提到是同域下的问题,优先处理Path配置即可解决。

内容的提问来源于stack exchange,提问作者Chase R Lewis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 06:42:37