问题描述:后端返回的Cookie,前端无法拿到

    解决方案:

    • 将CORSFilter中的过滤部分代码修改,”Access-Control-Allow-Origin” 的值不能再为”*”,改为调用方的url,代码如下:

      1. @Override
      2. public void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException {
      3. if(isCross) {
      4. HttpServletRequest httpServletRequest = (HttpServletRequest) servletRequest;
      5. HttpServletResponse httpServletResponse = (HttpServletResponse) servletResponse;
      6. System.out.println("拦截请求:" + httpServletRequest.getServletPath());
      7. // 这里做了修改
      8. //httpServletResponse.setHeader("Access-Control-Allow-Origin", "*");
      9. httpServletResponse.setHeader("Access-Control-Allow-Origin", httpServletRequest.getHeader("Origin"));
      10. httpServletResponse.setHeader("Access-Control-Allow-Methods", "POST,GET,OPTIONS,DELETE");
      11. httpServletResponse.setHeader("Access-Control-Max-Age", "0");
      12. httpServletResponse.setHeader("Access-Control-Allow-Headers", "Origin, No-Cache, X-Requested-With, If-Modified-Since, Pragma, Last-Modified, Cache-Control, " +
      13. " Expires, Content-Type, X-E4M-With,userId,token");
      14. httpServletResponse.setHeader("Access-Control-Allow-Credentials", "true");
      15. httpServletResponse.setHeader("XDomainRequestAllowed", "1");
      16. }
      17. filterChain.doFilter(servletRequest, servletResponse);
      18. }
    • 前端对应的要将axios的默认配置 withCredentials 设置为true,代码如下:

      1. // 为解决cookie跨域调用访问不到的问题
      2. axios.defaults.withCredentials = true
    • (好像没起作用)还有说配置nginx,但是在这里好像没有用处,具体的修改代码如下:

      1. // 添加了这一段,没啥用
      2. server {
      3. listen 8081;
      4. server_name localhost;
      5. proxy_set_header X-Forwarded-Host $host;
      6. proxy_set_header X-Forwarded-Server $host;
      7. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
      8. proxy_set_header Host $host;
      9. }

    总结

    通过上述的两个步骤,就使得前端拿到了后端返回的Cookie值,并在每次请求时会将Cookie值携带上去访问后端。第三个步骤,之后如果还有问题可以继续研究是否有效。