You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Chrome浏览器子iframe或弹窗无法携带HttpOnly Cookie问题

跨域场景下iframe子页面无法携带HttpOnly Cookie问题

场景说明

  • 父页面地址:https://sub1.some-domain.com
  • 嵌入的子iframe地址:https://sub2.some-domain.com
  • API服务地址:https://api.some-domain.com

操作流程与异常现象

  1. 父页面先向API发送POST请求,响应头如下:
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://sub1.some-domain.com
Set-Cookie:
 payload-name=payload-value;
 max-age=30;
 domain=some-domain.com;
 path=/;
 secure;
 samesite=none;
 httponly
  1. 子iframe向API发送GET请求,预期浏览器会自动携带HttpOnly Cookie payload-name=payload-value,但实际请求中未包含该Cookie。已确认fetch请求已配置credentials: "include",排除该配置问题影响。

补充信息

更新1:GET请求详情

请求代码:

fetch("https://api.some-domain.com/...", {
  "headers": {
    "accept": "application/json",
    "accept-language": "en-US,en;q=0.9,uk;q=0.8",
    "cache-control": "no-cache",
    "content-type": "application/json",
    "pragma": "no-cache",
    "sec-ch-ua": "\"Not/A)Brand\";v=\"99\", \"Google Chrome\";v=\"115\", \"Chromium\";v=\"115\"",
    "sec-ch-ua-mobile": "?0",
    "sec-ch-ua-platform": "\"Windows\"",
    "sec-fetch-dest": "empty",
    "sec-fetch-mode": "cors",
    "sec-fetch-site": "same-site"
  },
  "referrer": "https://sub2.some-domain.com/",
  "referrerPolicy": "strict-origin-when-cross-origin",
  "body": null,
  "method": "GET",
  "mode": "cors",
  "credentials": "include"
});

响应头:

Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://sub2.some-domain.com
Cache-Control: no-store,no-cache
Content-Encoding: gzip
Content-Type: application/json; charset=utf-8
Pragma: no-cache

更新2:本地环境测试结果

当三个域名均为https://localhost时,HttpOnly Cookie可正常携带,无异常现象。

更新3:弹窗窗口测试结果

将iframe替换为弹窗窗口发起请求时,出现同样的Cookie未携带问题。

内容的提问来源于stack exchange,提问作者Taras Yaremkiv

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 18:58:20