【问题标题】:Cookies with SameSite=None; Secure=true are not sent in all contexts. Chrome 91SameSite=None 的 Cookie; Secure=true 不会在所有上下文中发送。铬 91
【发布时间】:2021-09-03 05:23:00
【问题描述】:

我有一个托管在 https:/parent.example1.com 的 Web 应用程序,它嵌入了在 https:/child.example2.com 上运行的跨域 iframe。我控制这两个应用程序。

我需要使用 axios 从父应用向子域执行身份验证请求

const config = {
        headers: {
          Authorization: "Bearer XYZ",
          Accept: "application/json",
        },
        withCredentials: true,
    };

 axios.get("https://child.example2.com/auth", config)
     .then((response) => {
          ...
     })
     .catch((error) => {
        console.error(error);
    });

我没有收到 SameSite 或 Secure 错误/警告,这是响应中的 Set-Cookie 标头:

Set-Cookie : userId="Exaat3Na3NEAA3AYRmi6jeciH5dEafX"; Version=1; Max-Age=604800; Expires=Sat, 25-Jun-2021 13:51:54 GMT; Path=/; Secure; HttpOnly; SameSite=None

这个 cookie 应该与域 child.example2.com 相关联,但是当我刷新 iframe 时,浏览器由于某种原因没有发送 cookie。

当我使用 --disable-web-security 禁用 chrome web-security 时,它运行良好

我想知道我做错了什么?

【问题讨论】:

    标签: javascript google-chrome cookies cross-domain samesite


    【解决方案1】:

    来自https://child.example2.com 的服务器的响应应包含此标头:

    access-control-allow-credentials: true (this is one was missing)
    access-control-allow-origin: https:/parent.example1.com (and not * if the header above is set to true)

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2020-11-01
      • 1970-01-01
      • 1970-01-01
      • 2020-12-26
      • 2020-12-03
      • 1970-01-01
      相关资源
      最近更新 更多