You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Android旧版WebView为何在CORS请求中不传递Cookie?

Cordova旧版Android WebView CORS请求丢失会话Cookie问题

我开发的Cordova应用在与第三方API维持会话时遇到问题:API支持CORS,登录能成功获取会话Cookie,但旧版Android(7、8)的WebView在后续请求中无法传递该Cookie,Android 13则完全正常(服务器和客户端均未做任何修改)。请问如何强制旧版WebView实例在CORS请求中传递Cookie?

环境信息

Cordova版本

cordova --version
12.0.0 (cordova-lib@12.0.1)

config.xml配置

<?xml version='1.0' encoding='utf-8'?>
<widget id="com.test" version="1.0.0" xmlns="http://www.w3.org/ns/widgets" xmlns:cdv="http://cordova.apache.org/ns/1.0" xmlns:android="http://schemas.android.com/apk/res/android">
    <name>test</name>
    <description>test</description>
    <author email="admin@test.com" href="https://www.test.com">
        test
    </author>
    <content src="index.html" />
    <access origin="*" />
    <allow-intent href="*" />
    <allow-navigation href="*" />
    <preference name="scheme" value="https" />
    <preference name="hostname" value="www.myRemoteAPI.com"/>
    <preference name="android-minSdkVersion" value="25" />
    <preference name="android-targetSdkVersion" value="33" />
    <preference name="android-compileSdkVersion" value="33" />
    <icon src="./www/p/img/logoCirclet.png" />
    
    <platform name="android">
        <config-file target="AndroidManifest.xml" parent="/manifest">
            <uses-permission android:name="android.permission.CAMERA"/>
            <uses-permission android:name="android.permission.ACCESS_COARSE_LOCATION"/>
            <uses-permission android:name="android.permission.ACCESS_FINE_LOCATION"/>
            <uses-permission android:name="android.permission.READ_EXTERNAL_STORAGE"/>
        </config-file>
    </platform>
</widget>

登录响应头

Server: nginx/1.22.1
Date: Tue, 23 May 2023 14:18:06 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: keep-alive
set-cookie: _session=VEn26fd1uEKHFeSBZU4nw6dbYQXZrLSyTo6PGFbq8Q+jIIDKtmC5JX7A3yv+k9YErp2yWcmYKHPJXfLt+QYq2Sgu2RFYzXriBSK8ac/h11PPw; Max-Age=604800; Expires=Tue, 30 May 2023 14:18:05 GMT; Path=/; Secure; HttpOnly
x-envoy-upstream-service-time: 75
access-control-allow-origin: https://www.myRemoteAPI.com
access-control-allow-credentials: true
access-control-expose-headers: _session

后续请求头(Cookie缺失)

GET /k/usersfriends?limit=7&offset=0 HTTP/1.1
Host: www.myRemoteAPI.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Linux; Android 7.1.1; Android SDK built for x86 Build/NYC; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/55.0.2883.91 Mobile Safari/537.36
X-DevTools-Emulate-Network-Conditions-Client-Id: 1541fbf1-302d-41a2-b5f1-5d48cfc25864
Accept: */*
Referer: https://www.myRemoteAPI.com/
Accept-Encoding: gzip, deflate
Accept-Language: en-US
X-Requested-With: com.test

解决方法

1. 强制开启WebView第三方Cookie支持

旧版Android WebView(对应Chrome 55左右版本)对跨域Cookie处理更严格,需通过原生代码配置调整:
在项目的MainActivity.java中找到WebView初始化逻辑,添加以下代码:

CookieManager cookieManager = CookieManager.getInstance();
cookieManager.setAcceptCookie(true);
if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.LOLLIPOP) {
    cookieManager.setAcceptThirdPartyCookies(webView, true);
}

Android 5.0+需显式开启第三方Cookie支持,部分旧版WebView默认逻辑存在限制,此配置可强制启用跨域Cookie传递。

2. 确保请求携带withCredentials参数

前端发起CORS请求时,必须明确设置凭证携带选项,否则WebView不会自动传递Cookie:

  • 使用fetch:
fetch('https://www.myRemoteAPI.com/k/usersfriends?limit=7&offset=0', {
  method: 'GET',
  credentials: 'include'
})
  • 使用XMLHttpRequest:
var xhr = new XMLHttpRequest();
xhr.open('GET', 'https://www.myRemoteAPI.com/k/usersfriends?limit=7&offset=0');
xhr.withCredentials = true;
xhr.send();

3. 修正config.xml的跨域配置

当前access origin设为*,旧版WebView可能因此限制withCredentials生效,建议改为明确的API域名:

<access origin="https://www.myRemoteAPI.com" />

同时可尝试移除scheme和hostname配置,避免WebView误判同源关系,确保跨域请求逻辑触发正确的Cookie处理机制。

4. 更新Cordova Android平台

确保cordova-android版本为对应Cordova 12的最新稳定版,新版本可能修复了旧版WebView的Cookie处理bug:

cordova platform update android@12.0.0

内容的提问来源于stack exchange,提问作者Yonoss

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 11:00:23