jquery - $http请求不会在 Angular CORS中跨域发送cookie

标签 jquery angularjs cors

首先我想说,我已经阅读了 Stack 上的所有问题以及与 CORS 相关的所有内容,但实现仍然无法正常工作。我的应用程序构建在 angular crud demo 之上:

所以我在应用程序配置中有:

$httpProvider.defaults.useXDomain = true;
$httpProvider.defaults.withCredentials = true;
delete $httpProvider.defaults.headers.common['X-Requested-With'];

我知道它们设置正确(通过调试)。在我的“安全”应用程序中,我正在为当前用户发出跨域请求:

return $http.get(LAYOUT_CONFIG.baseURL + '/current-user').then(function(response) {
      //service.currentUser = response.data.user;
      service.currentUser = response.data;
      return service.currentUser;
    });

我在第一个请求时得到这些 header :

    Access-Control-Allow-Credentials:true
Access-Control-Allow-Headers:accept, origin, content-type, cookie
Access-Control-Allow-Methods:GET,POST
Access-Control-Allow-Origin:http://admin.vibetrace.com
Access-Control-Max-Age:1728000
Connection:keep-alive
Content-Encoding:gzip
Content-Type:text/html; charset=utf-8
Date:Sun, 02 Jun 2013 11:07:49 GMT
P3P:CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Server:nginx/1.1.19
Set-Cookie:vibetrace.ssid=s%3A2lT2_N0-EevCJt7LbRlJ6Az1.d8xp99st%2F0RNV0VN2D4o4AJXNRT%2F%2F46v8PDVWSAbx%2Fw; Path=/; Expires=Mon, 30 Sep 2013 11:07:49 GMT
Transfer-Encoding:chunked
Vary:Accept-Encoding
X-Cache:MISS
X-Powered-By:Express

所以 Set-Cookie 就在那里。但是,后续的 $http.get 请求(来自 Angular)不会发送之前应该设置的 cookie。

Accept:application/json, text/plain, */*
Accept-Encoding:gzip,deflate,sdch
Accept-Language:en-US,en;q=0.8
Cache-Control:no-cache
Connection:keep-alive
Host:app.vibetrace.com
Origin:http://admin.vibetrace.com
Pragma:no-cache
Referer:http://admin.vibetrace.com/
User-Agent:Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.93 Safari/537.36

但有趣的部分来了。如果我在控制台中运行以下代码:

$.ajax("https://app.vibetrace.com/current-user", {
            type: "GET",
            success: function(data, status, xhr) {               
            },
            xhrFields: {
                withCredentials: true
            },
            crossDomain: true
        });

请求 header 包含cookie。

Accept:*/*
Accept-Encoding:gzip,deflate,sdch
Accept-Language:en-US,en;q=0.8
Cache-Control:no-cache
Connection:keep-alive
Cookie:fbm_245656478789760=base_domain=.vibetrace.com; __utma=199448574.828439508.1336934706.1361539088.1361819816.356; __utmc=199448574; __utmz=199448574.1361819816.356.354.utmcsr=tenlister.com|utmccn=(referral)|utmcmd=referral|utmcct=/index.php; connect.sid=s%3AZ1o9bIw0jBOmQwuhKJDG1San.%2BfshIsvupiRuK0pUJqm8EAMnMBCyxf%2Fk17cAVzcy31w; __utma=173003172.1796845739.1355503443.1369827921.1369833348.68; __utmc=173003172; __utmz=173003172.1369410587.66.5.utmcsr=stage.marketizator.com|utmccn=(referral)|utmcmd=referral|utmcct=/app/builder/; vibetrace.ssid=s%3AV6biojefu9r5DTGErKL5vYPi.KAlnWMUm8jZmPV0MpP%2FrgqwmkF6WuXEZZDyzJhozYCs
Host:app.vibetrace.com
Origin:http://admin.vibetrace.com
Pragma:no-cache
Referer:http://admin.vibetrace.com/

我缺少什么?

最佳答案

你见过这个吗? Communication between AngularJS and a Jersey Webservice which are on a different domain. Can't access correct session

Try passing a config object to $http that specifies withCredentials, that should work in all versions.

$http({withCredentials: true, ...}).get(...)

这里的讨论:https://github.com/angular/angular.js/pull/1209

关于jquery - $http请求不会在 Angular CORS中跨域发送cookie,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/16882245/

相关文章:

javascript - 'Access-Control-Allow-Origin' header 是如何工作的?

javascript - 每 5 秒刷新一次 Fancybox

javascript - AngularJs 将带有子集合的对象发布到 MVC WebAPI

jquery - 从数据列表中选择项目时触发事件,而不是在键入时触发事件

javascript - 使用 $attrs 评估其中带有花括号的属性

javascript - 如何在 AngularJS 中将值从 Controller 传递到输入 HTML?

http - CORS 和 HTTP 基本身份验证

glassfish - JAX-RS 在 Glassfish 4 上启用 CORS(访问控制允许来源)

jquery - 重量级 Jquery 幻灯片在桌面上运行缓慢,在 ipad 2、android ics 和 iphone 上崩溃

javascript - 关于下拉菜单