Refused to set unsafe header "Cookie"

w3c规定,当请求的 header 匹配以下不安全字符时,将被终止:

  Accept-Charset
  Accept-Encoding
  Connection
  Content-Length
  Cookie
  Cookie2
  Content-Transfer-Encoding
  Expect
  Keep-Alive
  Referer
  Trailer
  Transfer-Encoding
  Upgrade