【问题标题】:Is there a way to not send cookies when making an XMLHttpRequest on the same origin?在同一来源上发出 XMLHttpRequest 时,有没有办法不发送 cookie?
【发布时间】:2016-08-20 09:38:53
【问题描述】:

我正在开发一个为用户解析 gmail rss 提要的扩展程序。如果他们不想保持登录状态,我允许用户指定用户名/密码。但是,如果用户已登录并且提供的用户名/密码用于不同的帐户,则这会中断多次登录。所以我想避免发送任何 cookie,但仍然能够在 send() 调用中发送用户名/密码。

【问题讨论】:

    标签: javascript ajax google-chrome-extension xmlhttprequest


    【解决方案1】:

    从 Chrome 42 开始,fetch API 允许 Chrome 扩展程序(以及一般的网络应用程序)执行无 cookie 请求。 HTML5 Rocks offers an introductory tutorial on using the fetch API.

    目前fetch 上的高级文档非常少,但API interface from the specification 是一个很好的起点。接口下面描述的fetch算法显示fetch生成的请求默认是没有凭据的!

    fetch('http://example.com/').then(function(response) {
        return response.text(); // <-- Promise<String>
    }).then(function(responseText) {
        alert('Response body without cookies:\n' + responseText);
    }).catch(function(error) {
        alert('Unexpected error: ' + error);
    });
    

    如果你想要真正的匿名请求,你也可以禁用缓存:

    fetch('http://example.com/', {
        // credentials: 'omit', // this is the default value
        cache: 'no-store',
    }).then(function(response) {
        // TODO: Handle the response.
        // https://fetch.spec.whatwg.org/#response-class
        // https://fetch.spec.whatwg.org/#body
    });
    

    【讨论】:

      【解决方案2】:

      您可以使用chrome.cookies module 来做到这一点。这个想法是获取当前的 cookie,保存它们,从浏览器的 cookie 存储中删除它们,发送您的请求,最后恢复它们:

      var cookies_temp = []; // where you put the cookies first
      var my_cookie_store = []; // the cookies will be there during the request
      var details = {/*your code*/}; // the first parameter for chrome.cookies.getAll()
      var start_kidnapping = function(cookies) {
          cookies_temp = cookies.slice();
          kidnap_cookie();
      };
      var kidnap_cookie = function() {
          // This recursive function will store the cookies from cookies_temp to
          // my_cookie_store and then remove them from the browser's cookie store.
          if (cookies_temp.length == 0) { // when no more cookies, end recursion
              send_request();
          };
          else {
              var cookie = cookies_temp.pop();
              // We store url as a property since it is useful later.
              // You may want to change the scheme.
              cookie.url = "http://" + cookie.domain + cookie.path;
              my_cookie_store.push(cookie); // save it
              chrome.cookies.remove({url: cookie.url, name: cookie.name}, kidnap_cookie);
          };
      };
      var send_request = function() {
          // Send your request here. It can be asynchronous.
          for (var i = 0, i < my_cookie_store.length; i++){
              delete cookie.hostOnly; // these 2 properties are not part of the
              delete cookie.session;  // object required by chrome.cookies.set()
              // note that at this point, cookie is no longer a Cookie object
              chrome.cookies.set(my_cookie_store[i]); // restore cookie
          };
          my_cookie_store = []; // empty it for new adventures
      };
      chrome.cookies.getAll(details, start_kidnapping); // start
      

      或者,一个更简单的解决方案是使用chrome.windows module 打开一个将发送请求的隐身窗口,但这会阻止您与扩展程序的其余部分进行通信。请注意,您可能需要将清单的 incognito 属性更改为 split

      var incognito_window = {
          "url": "incognito.html",
          "focused": false, // do not bother user
          "incognito": true
      }
      chrome.windows.create(incognito_window);
      

      【讨论】:

      • delete cookie.hostOnly;delete cookie.session; 行应该分别是 delete my_cookie_store[i].hostOnly;delete my_cookie_store[i].session; 吗?
      猜你喜欢
      • 2011-05-21
      • 1970-01-01
      • 2012-10-19
      • 2011-10-26
      • 1970-01-01
      • 1970-01-01
      • 2020-02-23
      • 1970-01-01
      • 2020-03-07
      相关资源
      最近更新 更多