ASP.NET Core 7跨域Cookie无法在本地浏览器保存求助
环境信息
- 前端:运行在
https://localhost:3001的NextJS应用(已启用HTTPS) - 后端:部署在IIS上、端口为
localhost:55379的ASP.NET Core 7 Web API
已做配置尝试
前端POST请求已携带Credentials: true(也试过include,无差异)请求头,且已尝试调整SameSite、Secure、Domain、Path、HttpOnly等所有可能的Cookie配置组合。
后端CORS配置
// Cors builder.Services.AddCors(options => { options.AddPolicy(name: "AllowAll", policy => policy .WithOrigins("https://localhost:3001") .AllowAnyMethod() .AllowAnyHeader() .AllowCredentials() .WithExposedHeaders("Token-Expired")); });
控制器Login方法设置Cookie代码
// Set token cookies CookieOptions optionsToken = new() { Expires = authenticationResponse.Expiration, IsEssential = true, SameSite = SameSiteMode.None, Secure = true, HttpOnly = false, Domain = "localhost", }; CookieOptions optionsRefreshToken = new() { Expires = authenticationResponse.RefreshTokenExpiration, IsEssential = true, SameSite = SameSiteMode.None, Secure = true, HttpOnly = false, Domain = "localhost", }; Response.Cookies.Append("Bearer", JsonSerializer.Serialize(authenticationResponse.Token), optionsToken); Response.Cookies.Append("RefreshToken", JsonSerializer.Serialize(authenticationResponse.RefreshToken), optionsRefreshToken);
请求完整头信息
GENERAL
Request URL: http://localhost:55379/api/user/Login Request Method: POST Status Code: 200 OK Remote Address: [::1]:55379 Referrer Policy: strict-origin-when-cross-origin
RESPONSE
HTTP/1.1 200 OK Cache-Control: no-cache,no-store Pragma: no-cache Transfer-Encoding: chunked Content-Type: application/json; charset=utf-8 Expires: Thu, 01 Jan 1970 00:00:00 GMT Server: Microsoft-IIS/10.0 Set-Cookie: .AspNetCore.Identity.Application=CfDJ8PW29-... [TRUNCATED] ...Z71SFnWf1NlM; path=/; samesite=lax; httponly Set-Cookie: Bearer=%22eyJhbGciOiJIUzI1NiIsInR5cCI6 ... [TRUNCATED] ... IkpXVCJ9.e3AeD6pKb24lmp386OoJfFQ_Z_w%22; max-age=10799; domain=localhost; path=/; secure; samesite=none Set-Cookie: RefreshToken=%22fmP4LXNvuGooMN0%5C... [TRUNCATED] ...gkCus228QX9V%5Cu002B5rQqa7LjLzElpfTcpw%3D%3D%22; max-age=14799; domain=localhost; path=/; secure; samesite=none Access-Control-Allow-Origin: https://localhost:3001 Access-Control-Allow-Credentials: true X-Powered-By: ASP.NET Date: Fri, 10 Nov 2023 19:19:28 GMT
REQUEST
POST /api/user/Login HTTP/1.1 Accept: application/json Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9,fi;q=0.8,et;q=0.7 Connection: keep-alive Content-Length: 59 Content-Type: application/json Credentials: true Host: localhost:55379 Origin: https://localhost:3001 Sec-Fetch-Dest: empty Sec-Fetch-Mode: cors Sec-Fetch-Site: cross-site User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 sec-ch-ua: "Google Chrome";v="119", "Chromium";v="119", "Not?A_Brand";v="24" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows"
问题现象
Chrome响应中能看到Cookie(但不显示Bearer Cookie,Firefox可正常显示),但浏览器Application -> Cookies中无任何保存的Cookie。
解决方案
- 修正后端请求协议:当前后端使用
http://localhost:55379,但前端是HTTPS环境,Secure=true的Cookie仅能在HTTPS下保存,需将后端配置为HTTPS,确保请求URL为https://localhost:55379。 - 移除Domain配置:针对localhost域名,手动设置
Domain="localhost"可能触发浏览器的安全限制,删除CookieOptions中的Domain属性,让浏览器自动处理域名映射。 - 规范前端Credentials参数:将前端请求的
credentials参数明确设为"include"(部分请求库对布尔值解析存在兼容问题),示例:fetch('https://localhost:55379/api/user/Login', { method: 'POST', credentials: 'include', // 其他请求配置 }) - Chrome本地调试特殊处理:Chrome对localhost的HTTPS Cookie有严格限制,可尝试:
- 在地址栏输入
chrome://flags/#allow-insecure-localhost,启用该选项后重启浏览器 - 用自定义本地域名(如
local.test)替代localhost,修改hosts文件映射到127.0.0.1,并配置对应HTTPS证书
- 在地址栏输入
内容的提问来源于stack exchange,提问作者Ettur
相关产品推荐
相关产品推荐

