生产环境下基于JWT认证的Secure HttpOnly Cookie未设置求助
背景
我开发了一套基于JWT的认证系统,通过HttpOnly、Secure Cookie传输令牌。登录请求的响应头信息如下:
access-control-allow-credentials: true access-control-allow-headers: Content-Type, Authorization, X-Requested-With access-control-allow-methods: GET, POST, PUT, DELETE, OPTIONS access-control-allow-origin: https://mysite.example.com access-control-max-age: 3600 date: Wed, 08 Apr 2026 07:29:36 GMT server: nginx set-cookie: access-token=********; expires=Thu, 09 Apr 2026 00:00:00 GMT; httponly; secure; samesite=None; path=/; domain=.example.com set-cookie: refresh-token=********; expires=Wed, 15 Apr 2026 00:00:00 GMT; httponly; secure; samesite=None; path=/; domain=.example.com
问题
仅在生产环境中,Cookie无法在浏览器的Application > Cookies中被设置;而在开发环境(localhost:5173)中一切正常,Cookie能正常设置。
我已尝试在自定义axios apiClient中添加withCredentials: true,但没有效果。请问还遗漏了什么配置?
更新
使用正确的HTTP头命名规范后问题解决,浏览器不会忽略大小写(例如:"expires"应改为"Expires")。
内容的提问来源于stack exchange,提问作者AlbertDeTerre
相关产品推荐
相关产品推荐

