ajax跨域访问cookie丢失的解决方法
ajax跨域访问,可以使用jsonp方法或设置Access-Control-Allow-Origin实现,关于设置Access-Control-Allow-Origin实现跨域访问可以参考之前我写的文章《ajax 设置Access-Control-Allow-Origin实现跨域访问》 1.ajax跨域访问,cookie丢失首先创建两个测试域名 测试代码 setcookie.php 用于设置服务端cookie <?php setcookie('data',time(),time()+3600); ?>
<?php $name = isset($_POST['name'])? $_POST['name'] : ''; $ret = array( 'success' => true,'name' => $name,'cookie' => isset($_COOKIE['data'])? $_COOKIE['data'] : '' ); // 指定允许其他域名访问 header('Access-Control-Allow-Origin:http://a.fdipzone.com'); // 响应类型 header('Access-Control-Allow-Methods:POST'); // 响应头设置 header('Access-Control-Allow-Headers:x-requested-with,content-type'); header('content-type:application/json'); echo json_encode($ret); ?>
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="content-type" content="text/html;charset=utf-8">
<script src="//code.jquery.com/jquery-1.11.0.min.js"></script>
<title> ajax 跨域访问cookie丢失的解决方法 </title>
</head>
<body>
<script type="text/javascript"> $(function(){ $.ajax({ url: 'http://b.fdipzone.com/server.php',// 跨域 dataType: 'json',type: 'post',data: {'name':'fdipzone'},success:function(ret){ if(ret['success']==true){ alert('cookie:' + ret['cookie']); } } }); }) </script>
</body>
</html>
首先先执行http://b.fdipzone.com/setcookie.php,创建服务端cookie。 输出 {"success":true,"name":"fdipzone","cookie":""}
获取cookie失败。 2.解决方法客户端 服务端 header("Access-Control-Allow-Credentials:true");
允许请求带有验证信息 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="content-type" content="text/html;charset=utf-8">
<script src="//code.jquery.com/jquery-1.11.0.min.js"></script>
<title> ajax 跨域访问cookie丢失的解决方法 </title>
</head>
<body>
<script type="text/javascript"> $(function(){ $.ajax({ url: 'http://b.fdipzone.com/server.php',// 跨域 xhrFields:{withCredentials: true},// 发送凭据 dataType: 'json',success:function(ret){ if(ret['success']==true){ alert('cookie:' + ret['cookie']); } } }); }) </script>
</body>
</html>
<?php $name = isset($_POST['name'])? $_POST['name'] : ''; $ret = array( 'success' => true,content-type'); // 是否允许请求带有验证信息 header('Access-Control-Allow-Credentials:true'); header('content-type:application/json'); echo json_encode($ret); ?>
按之前步骤执行,请求返回 {"success":true,"cookie":"1484558863"}
获取cookie成功 3.注意事项1.如果客户端设置了withCredentials属性设置为true,而服务端没有设置Access-Control-Allow-Credentials:true,请求时会返回错误。 XMLHttpRequest cannot load http://b.fdipzone.com/server.php. Credentials flag is 'true',but the 'Access-Control-Allow-Credentials' header is ''. It must be 'true' to allow credentials. Origin 'http://a.fdipzone.com' is therefore not allowed access.
2.服务端header设置Access-Control-Allow-Credentials:true后,Access-Control-Allow-Origin不可以设为*,必须设置为一个域名,否则回返回错误。 XMLHttpRequest cannot load http://b.fdipzone.com/server.php. A wildcard '*' cannot be used in the 'Access-Control-Allow-Origin' header when the credentials flag is true. Origin 'http://a.fdipzone.com' is therefore not allowed access. The credentials mode of an XMLHttpRequest is controlled by the withCredentials attribute.
(编辑:李大同) 【声明】本站内容均来自网络,其相关言论仅代表作者个人观点,不代表本站立场。若无意侵犯到您的权利,请及时与联系站长删除相关内容! |