How to allow Azure CDN (Standard Microsoft) to allow "set-cookie" for "ASP.NET_SessionId"?

Viewed 1088

My site uses ASP.NET_SessionId cookies. This is standard ASP.NET header used for session management. CDN itself removes some headers from the response: in this case, the browser is not receiving "set-cookie" header for "ASP.NET_SessionId", despite the fact, it was sent by the web site (see screenshots below).

The home page is dynamic and is not intended to be cached. Also, page sets "no-cache" header.

This happens only with Azure CDN with Standard Microsoft profile.

Could you please provide any ideas on how to allow set-cookie to pass-through the CDN?


Original response headers:

Original Headers (two)

Original Headers (two)

As you can see there are two "Set-Cookie" headers.


CDN-ified response headers:

Headers with CDN (one)

Headers with CDN (one)

As you can see only one "Set-Cookie" header left, "ASP.NET_SessionId" is removed by CDN (some security rule?).


I cannot find any documentation on how to allow all headers to pass-through.

Thank you!

1 Answers

It seems that the ASP.NET session ID could not be cached as CDN could not cache such resources:

Dynamic resources that change frequently or are unique to an individual user cannot be cached.

You can get more details about how CDN caching works.

Related