NGINX静态资源无Cookie域名配置求助:fastcgi_hide_header无效
Hey there, let's break down why your fastcgi_hide_header Set-Cookie; didn't work and get this sorted out properly.
First off, the key mistake here: fastcgi_hide_header only applies to requests processed via FastCGI (like PHP or other dynamic scripts). Since you're serving static assets (images, CSS, JS, etc.), NGINX handles these directly without going through FastCGI—so that directive was never being triggered for your static content at all.
Here's the correct approach to turn assets.example.com into a cookieless domain:
Step 1: Use a dedicated server block for assets
Make sure you have a separate server block for assets.example.com (distinct from your main example.com config). This lets you isolate cookie settings specifically for static resources.
Step 2: Configure NGINX to avoid Set-Cookie headers for static assets
Add these rules to your assets.example.com server block to ensure no cookies are sent in responses:
server { listen 80; listen [::]:80; server_name assets.example.com; # Path to your static assets directory root /var/www/assets; # Global rule for all assets location / { # Strip any Set-Cookie headers inherited from global configs proxy_hide_header Set-Cookie; fastcgi_hide_header Set-Cookie; # Just in case any dynamic content slips through # Force an empty Set-Cookie header to override accidental settings add_header Set-Cookie ""; # Optional: Set long cache expiry for static assets (boosts performance) expires 1y; add_header Cache-Control "public, immutable"; access_log off; # Reduce log noise for static requests } # Optional: Explicit rules for common static file types (more precise) location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|woff|woff2)$ { expires 1y; add_header Cache-Control "public, immutable"; proxy_hide_header Set-Cookie; fastcgi_hide_header Set-Cookie; add_header Set-Cookie ""; } }
Step 3: Check for cross-domain cookie leakage
If Pingdom still flags the issue after applying the above, it might be because your main example.com domain sets cookies with a domain=.example.com attribute. This makes browsers send those cookies to all subdomains (including assets.example.com). To fix this:
- Update your main domain's cookie settings to use
domain=example.com(without the leading dot) so cookies only apply to the root domain, not subdomains. - If you can't modify the main domain's cookies, consider switching to a completely separate domain for assets (like
assets-example.com) instead of a subdomain—this guarantees no cookie sharing.
Step 4: Test and apply the config
- Validate your NGINX config to avoid syntax errors:
sudo nginx -t - Reload NGINX to apply changes:
sudo systemctl reload nginx - Verify with curl that no Set-Cookie header is present:
Look for the absence of acurl -I https://assets.example.com/your-test-image.jpgSet-Cookieline in the response headers.
That should resolve the Pingdom warning and get your static assets serving from a cookieless domain.
内容的提问来源于stack exchange,提问作者K M

