Windows Server(IIS)部署Node.js与Next.js应用的会话Cookie异常问题
我有两个应用要部署在Windows Server上:
- 跑在5000端口的Node.js API服务,仅提供接口
- 跑在3000端口的Next.js前端应用,面向用户访问
用IIS做反向代理后,出现会话和Cookie传递异常,具体表现为UI显示混乱——比如登录后同时出现登录页和仪表盘,退出账号后还能继续操作应用。
现有配置文件
API(Node.js)的web.config
<?xml version="1.0" encoding="UTF-8"?> <configuration> <system.webServer> <rewrite> <rules> <rule name="api" stopProcessing="true"> <match url="(.*)" /> <action type="Rewrite" url="http://localhost:5000/{R:1}" /> </rule> </rules> </rewrite> </system.webServer> </configuration>
Next.js应用的web.config
<?xml version="1.0" encoding="UTF-8"?> <configuration> <system.webServer> <rewrite> <rules> <rule name="web" stopProcessing="true"> <match url="(.*)" /> <action type="Rewrite" url="http://localhost:3000/{R:0}" /> </rule> </rules> </rewrite> </system.webServer> </configuration>
IIS站点配置截图

问题根源与修复方法
核心原因
当前配置仅做了URL重写,未处理Cookie转发和会话关联。IIS默认不会把客户端的Cookie正确传递给后端服务,也不会将后端设置的Cookie调整为客户端可识别的格式,直接导致会话状态混乱。
一步步修复
1. 安装IIS ARR核心模块
ARR是IIS实现反向代理的必备组件,需确认已安装:
- 打开IIS管理器,点击服务器节点,查看功能视图中是否有「Application Request Routing Cache」
- 未安装的话,通过Web平台安装器搜索下载该模块
2. 更新两个应用的web.config,添加代理与Cookie处理规则
API应用的web.config(更新后)
<?xml version="1.0" encoding="UTF-8"?> <configuration> <system.webServer> <rewrite> <rules> <rule name="api" stopProcessing="true"> <match url="(.*)" /> <action type="Rewrite" url="http://localhost:5000/{R:1}" /> <!-- 配置代理相关变量 --> <serverVariables> <set name="HTTP_X_ORIGINAL_ACCEPT_ENCODING" value="{HTTP_ACCEPT_ENCODING}" /> <set name="HTTP_ACCEPT_ENCODING" value="" /> </serverVariables> </rule> </rules> <!-- 修正后端返回的Cookie域名和路径 --> <outboundRules> <rule name="Rewrite API Cookies" preCondition="ResponseHasSetCookie"> <match serverVariable="RESPONSE_Set_Cookie" pattern="^(.*; domain=)localhost(:5000)?(.*)$" /> <!-- 替换为你的公网域名 --> <action type="Rewrite" value="{R:1}你的公网域名{R:3}" /> </rule> <rule name="Rewrite API Cookie Path" preCondition="ResponseHasSetCookie"> <match serverVariable="RESPONSE_Set_Cookie" pattern="^(.*; path=)/?(.*)$" /> <!-- 适配IIS站点路径 --> <action type="Rewrite" value="{R:1}/api/{R:2}" /> </rule> <preConditions> <preCondition name="ResponseHasSetCookie"> <add input="{RESPONSE_Set_Cookie}" pattern=".+" /> </preCondition> </preConditions> </outboundRules> </rewrite> <!-- 启用代理并保留请求头 --> <proxy enabled="true" preserveHostHeader="true" reverseRewriteHostInResponseHeaders="true" /> <httpProtocol> <customHeaders> <remove name="X-Powered-By" /> </customHeaders> </httpProtocol> </system.webServer> </configuration>
Next.js应用的web.config(更新后)
<?xml version="1.0" encoding="UTF-8"?> <configuration> <system.webServer> <rewrite> <rules> <rule name="web" stopProcessing="true"> <match url="(.*)" /> <action type="Rewrite" url="http://localhost:3000/{R:0}" /> <serverVariables> <set name="HTTP_X_ORIGINAL_ACCEPT_ENCODING" value="{HTTP_ACCEPT_ENCODING}" /> <set name="HTTP_ACCEPT_ENCODING" value="" /> </serverVariables> </rule> </rules> <!-- 修正Next.js返回的Cookie域名 --> <outboundRules> <rule name="Rewrite Web Cookies" preCondition="ResponseHasSetCookie"> <match serverVariable="RESPONSE_Set_Cookie" pattern="^(.*; domain=)localhost(:3000)?(.*)$" /> <!-- 替换为你的公网域名 --> <action type="Rewrite" value="{R:1}你的公网域名{R:3}" /> </rule> <preConditions> <preCondition name="ResponseHasSetCookie"> <add input="{RESPONSE_Set_Cookie}" pattern=".+" /> </preCondition> </preConditions> </outboundRules> </rewrite> <proxy enabled="true" preserveHostHeader="true" reverseRewriteHostInResponseHeaders="true" /> <httpProtocol> <customHeaders> <remove name="X-Powered-By" /> </customHeaders> </httpProtocol> </system.webServer> </configuration>
3. 调整后端应用的Cookie设置
- Node.js API:设置Cookie时,将
domain改为你的公网域名,path设为/api;若使用HTTPS,开启secure属性,SameSite设为Lax或None(跨域场景) - Next.js:若使用内置会话或自定义Cookie,同样将
domain改为公网域名,确保客户端能正常识别
4. 验证测试
- 重启IIS站点和两个后端应用
- 清除浏览器缓存与Cookie,重新登录测试,检查页面显示、登录退出流程是否恢复正常
内容的提问来源于stack exchange,提问作者Rawand
相关产品推荐
相关产品推荐

