You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Vue中Axios请求Node后端无法携带Session ID,新会话重复生成问题

问题:Vue前端通过Axios请求Node.js后端无法保持Session会话

我正在Vue前端用Axios向Node.js后端发送携带Session ID的请求,实现管理员会话管理。登录成功后跳转至根路径,组件挂载前会调用validateAdmin接口验证凭证,但每次请求都会生成新的Session ID,无法保持会话。Session数据已存入SQLite3的sessions表,试过设置rolling: false及添加req.session.touch()中间件,问题仍未解决。

登录逻辑代码

axios.defaults.withCredentials = true;
const submit = async (data) => {
  const { email, password } = data;
  const url = "http://localhost:5000/api/v1/users/loginAdmin";

  try {
    const res = await axios.post(url, {
      email,
      password,
    });
    error.value = undefined;
    console.log(res.data);
    const loginIng = useLogin();
    loginIng.logIn(res.data);
    router.push("/");
  } catch (err) {
    console.log(err);
    error.value = err.response.data.message;
  }
};

凭证验证代码

axios.defaults.withCredentials = true;
setup() {
const login = useLogin();
const router = useRouter();
onBeforeMount(() => {
  axios
    .post("http://localhost:5000/api/v1/users/validateAdmin")
    .then((res) => {
      login.logIn(res.data);
    })
    .catch((err) => {
      console.log(err);
      router.push("/login");
    });
});
return {};
}

后端Session配置

app.use(
  session({
    store: new KnexSessionStore({
      knex: db,
      tablename: "sessions",
    }),
    secret: process.env.SECRET,
    resave: false,
    saveUninitialized: false,
    cookie: {
      maxAge: 1000 * 60 * 60 * 24,
      secure: process.env.NODE_ENV === "production",
    },
  })
);

登录接口代码

const loginAdmin = async (req, res) => {
    req.session.user = admin;
}

验证接口代码

const validateAdmin = async (req, res) => {
  const userSession = req.session;
  const user = userSession.user;
}

已尝试的解决方案

  • 设置rolling: false
  • 添加req.session.touch()中间件

可行解决方向

1. 修复跨域CORS配置

后端必须显式配置CORS允许携带凭证,且不能用通配符*作为origin:

const cors = require('cors');
app.use(cors({
  origin: 'http://localhost:你的前端端口', // 例如3000
  credentials: true
}));

2. 手动触发Session保存

登录接口修改req.session后,手动调用save()确保会话持久化:

const loginAdmin = async (req, res) => {
    req.session.user = admin;
    req.session.save(err => {
      if (err) return res.status(500).json({ message: '会话保存失败' });
      res.json(admin);
    });
}

3. 调整Cookie的sameSite属性

开发环境下显式设置sameSite: 'lax',避免浏览器拦截Cookie:

cookie: {
  maxAge: 1000 * 60 * 60 * 24,
  secure: process.env.NODE_ENV === "production",
  sameSite: process.env.NODE_ENV === "production" ? 'none' : 'lax'
}

4. 验证请求地址一致性

确保前端Axios请求的域名+端口和后端完全匹配,比如前端用http://localhost:3000,后端用http://localhost:5000,不要混用IP和localhost,否则Cookie的domain不匹配会导致无法携带。

5. 检查KnexSessionStore配置

确认SQLite3的sessions表存在,Knex连接的数据库正确。登录后打印req.session.id,去数据库中查询该ID是否存在,验证会话是否被正确存储。

内容的提问来源于stack exchange,提问作者Twfyq Bhyry

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 22:00:57