You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Blazor WebAssembly调用Web API无法获取Cookie问题求助

解决Blazor WebAssembly调用Web API时Cookie无法传递的问题

1. 修正Web API的跨域(CORS)配置

跨域场景下必须允许携带凭据,且不能用通配符*作为允许来源:

builder.Services.AddCors(options =>
{
    options.AddPolicy("BlazorCorsPolicy", policy =>
    {
        // 替换为你的Blazor客户端实际地址,比如https://localhost:5001
        policy.WithOrigins("https://your-blazor-client-url")
              .AllowAnyHeader()
              .AllowAnyMethod()
              .AllowCredentials(); // 关键配置:允许携带Cookie等凭据
    });
});

// 注意中间件顺序:放在UseRouting之后,UseAuthorization之前
app.UseCors("BlazorCorsPolicy");

2. 配置Blazor客户端的HttpClient

确保请求时自动携带Cookie:

// 注册带凭据的HttpClient
builder.Services.AddHttpClient("ApiClient", client =>
{
    client.BaseAddress = new Uri("https://your-web-api-url"); // 替换为你的API地址
}).ConfigurePrimaryHttpMessageHandler(() => new HttpClientHandler
{
    UseCookies = true,
    AllowAutoRedirect = true
});

// 组件中调用API时,显式指定包含凭据
var response = await httpClient.GetFromJsonAsync<UserInfo>("api/user/current", 
    new HttpRequestMessageOptions
    {
        Credentials = FetchApiCredentials.Include
    });

3. 调整Cookie的设置参数

Web API设置Cookie时,必须适配跨域场景:

Response.Cookies.Append("abc", "your-cookie-value", new CookieOptions
{
    HttpOnly = true, // 防XSS安全配置
    Secure = true, // 生产HTTPS环境必须开启,本地HTTP可设为false
    SameSite = SameSiteMode.None, // 跨域场景下的必要设置
    Domain = ".your-domain.com", // 若客户端与API为同主域不同子域,设置主域
    Expires = DateTimeOffset.UtcNow.AddDays(7)
});

4. 浏览器端验证

打开浏览器开发者工具(F12)→ Network面板:

  • 检查API请求的Request Headers是否包含Cookie: abc=xxx
  • 检查Response Headers的Set-Cookie是否符合上述配置,若浏览器标记Cookie为"被阻止",则说明SameSite/Secure参数配置错误

内容的提问来源于stack exchange,提问作者maztt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 00:45:11