You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot中子域名Cookie无法随后续请求提交问题

Hey there, let's tackle this cookie issue you're facing—when your Spring Boot backend sets a cookie that shows up in the browser, but it doesn't get carried over in subsequent requests to your subdomain (secure.stgapi.py.com from stgapi.py.com). I'll walk through the most common pitfalls and actionable fixes:

Common Causes & Solutions

1. Incorrect Domain Configuration

Browser cookie rules are specific about domain matching, and small misconfigurations here are often the culprit:

  • If you set the cookie's domain to .py.com (with a leading dot), modern browsers treat this the same as py.com—it should be sent to all subdomains of py.com, including both stgapi.py.com and secure.stgapi.py.com.
  • However, many modern browsers ignore leading dots now, so try setting the domain to py.com (no leading dot) instead for broader compatibility.
  • If you only want the cookie to apply to stgapi.py.com and its direct subdomains (like secure.stgapi.py.com), set the domain to stgapi.py.com—this ensures the cookie is sent to both the parent domain and its subdomains.

2. Missing or Misconfigured SameSite Attribute

Modern browsers default to SameSite=Lax for cookies, but explicit configuration avoids ambiguity:

  • For HTTP environments (like your staging setup), set SameSite=Lax explicitly. This allows the cookie to be sent with AJAX requests from the parent domain to the subdomain, while still providing basic security against CSRF.
  • Avoid SameSite=Strict here—it would only send the cookie when navigating directly to the subdomain (e.g., clicking a link), not for AJAX requests initiated from stgapi.py.com.
  • Do not use SameSite=None unless you're using HTTPS—this flag requires the Secure attribute, which is invalid for HTTP requests.

3. Accidental Secure Flag

If your cookie has the Secure attribute enabled, browsers will only send it over HTTPS. Since your setup uses HTTP, this flag will block the cookie from being sent in requests. Double-check your Spring Boot code to ensure this flag is omitted.

4. Stale Browser Cache

Old cookies with conflicting domain or SameSite settings might be overriding your new configuration. Clear your browser's cookie cache for stgapi.py.com and secure.stgapi.py.com, then retest from scratch.

Working Spring Boot Code Examples

Here are two reliable ways to set the cookie correctly in Spring Boot:

Using ResponseCookie (Recommended for Spring 5+)

import org.springframework.http.HttpHeaders;
import org.springframework.http.ResponseCookie;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;

import javax.servlet.http.HttpServletResponse;
import java.time.Duration;

@RestController
public class CookieController {

    @GetMapping("/set-cookie")
    public ResponseEntity<String> setCookie(HttpServletResponse response) {
        ResponseCookie authCookie = ResponseCookie.from("auth_token", "your-unique-token")
                .domain("stgapi.py.com") // Adjust to "py.com" if you want all subdomains
                .path("/")
                .maxAge(Duration.ofHours(24))
                .sameSite("Lax")
                .build();

        response.addHeader(HttpHeaders.SET_COOKIE, authCookie.toString());
        return ResponseEntity.ok("Cookie configured successfully");
    }
}

Using Traditional Cookie Object

import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;

import javax.servlet.http.Cookie;
import javax.servlet.http.HttpServletResponse;

@RestController
public class CookieController {

    @GetMapping("/set-cookie")
    public String setCookie(HttpServletResponse response) {
        Cookie authCookie = new Cookie("auth_token", "your-unique-token");
        authCookie.setDomain("stgapi.py.com"); // Adjust to "py.com" as needed
        authCookie.setPath("/");
        authCookie.setMaxAge(24 * 60 * 60); // 24 hours in seconds
        authCookie.setSameSite("Lax");

        response.addCookie(authCookie);
        return "Cookie set successfully";
    }
}

Verification Steps

  1. Visit http://stgapi.py.com/set-cookie to set the cookie.
  2. Open your browser's DevTools → Application → Cookies → stgapi.py.com. Confirm:
    • Domain matches what you configured (e.g., stgapi.py.com).
    • SameSite is set to Lax.
    • Secure is unchecked.
  3. Trigger an AJAX request to http://secure.stgapi.py.com and check the Request Headers—you should see the Cookie header with your token.

内容的提问来源于stack exchange,提问作者Priank

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:26:22