doufangzhang4454 2015-07-02 08:36
浏览 68

在domainB.com上阅读domainA.com上的cookie

I know browsers block cross domain cookies for security reasons. I'm wondering if there is a way around it? I have a WP website and also a url shortener, the URL shortener does some tracking by grabbing the WP username from the cookie, if it is set.

I've moved my url shortener to a new short domain and obviously the tracking system has stopped grabbing the username from the cookie. Is there any way I can reintroduce this functionality?

  • 写回答

1条回答 默认 最新

  • douyu9433 2015-07-02 08:54
    关注

    Cross domain can be allowed by the header Access-Control-Allow-Origin: *.

    But you cannot share cookies through domains.

    An alternative solution from this SO anwser:

    You could do something like this:

    • centrilize all cokies in a single domain, let's say cookiemaker.com
    • when the user makes a request to example.com you redirect him to cookimaker.com
    • cookiemaker.com redirects him back to example.com with the information you need

    Of course, it's not completelly secure, and you have to create some kind of internal protocol between your apps to do that.

    评论

报告相同问题?

悬赏问题

  • ¥15 关于#matlab#的问题:期望的系统闭环传递函数为G(s)=wn^2/s^2+2¢wn+wn^2阻尼系数¢=0.707,使系统具有较小的超调量
  • ¥15 FLUENT如何实现在堆积颗粒的上表面加载高斯热源
  • ¥30 截图中的mathematics程序转换成matlab
  • ¥15 动力学代码报错,维度不匹配
  • ¥15 Power query添加列问题
  • ¥50 Kubernetes&Fission&Eleasticsearch
  • ¥15 報錯:Person is not mapped,如何解決?
  • ¥15 c++头文件不能识别CDialog
  • ¥15 Excel发现不可读取的内容
  • ¥15 关于#stm32#的问题:CANOpen的PDO同步传输问题