检查代码逻辑,当客户端不需要读取cookie时,将HttpOnly属性设为true。 Cookie cookie = new Cookie("myCookieName", value);cookie.setHttpOnly(true);