You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

生产环境下基于JWT认证的Secure HttpOnly Cookie未设置求助

基于JWT的认证系统Cookie生产环境设置问题

背景

我开发了一套基于JWT的认证系统,通过HttpOnly、Secure Cookie传输令牌。登录请求的响应头信息如下:

access-control-allow-credentials: true
access-control-allow-headers: Content-Type, Authorization, X-Requested-With
access-control-allow-methods: GET, POST, PUT, DELETE, OPTIONS
access-control-allow-origin: https://mysite.example.com
access-control-max-age: 3600
date: Wed, 08 Apr 2026 07:29:36 GMT
server: nginx
set-cookie: access-token=********; expires=Thu, 09 Apr 2026 00:00:00 GMT; httponly; secure; samesite=None; path=/; domain=.example.com
set-cookie: refresh-token=********; expires=Wed, 15 Apr 2026 00:00:00 GMT; httponly; secure; samesite=None; path=/; domain=.example.com

问题

仅在生产环境中,Cookie无法在浏览器的Application > Cookies中被设置;而在开发环境(localhost:5173)中一切正常,Cookie能正常设置。

我已尝试在自定义axios apiClient中添加withCredentials: true,但没有效果。请问还遗漏了什么配置?

更新

使用正确的HTTP头命名规范后问题解决,浏览器不会忽略大小写(例如:"expires"应改为"Expires")。


内容的提问来源于stack exchange,提问作者AlbertDeTerre

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.01 13:14:58