feat: 云闪付入口 token 自动登录及权益状态恢复

- 新增 open-api/hhService/tokenDecode 封装,URL 带 token 时自动解码登录并刷新资格
- 解码失败降级为手机号登录,并用 replaceState 清除地址栏 token 防泄露
- 权益页已登录未认证时自动恢复认证状态,认证取消后停留认证页

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
This commit is contained in:
jacobxu666
2026-08-27 15:17:08 +08:00
co-authored by Claude Haiku 4.5
parent 8d57cf7f92
commit 06e8223c27
4 changed files with 105 additions and 4 deletions
+50 -2
View File
@@ -59,10 +59,56 @@
]
}
},
onLoad() {
onLoad(options) {
if (options.token) {
this.handleTokenLogin(options.token)
}
this.getLocation()
},
methods: {
// xuchao: 云闪付入口 token 自动登录
handleTokenLogin(token) {
this.$u.api.tokenDecode({ token }).then(res => {
if (res.errcode === 0 && res.data && res.data.mobile) {
uni.setStorageSync('phone', res.data.mobile)
this.$u.api.getEligibility({ phone: res.data.mobile, identityNo: res.data.idNo || '', name: res.data.name || '' }).then(eRes => {
if (eRes.errcode === 0) {
uni.setStorageSync('isAuth', eRes.data.isAuth)
uni.setStorageSync('hasWin', eRes.data.hasWin)
uni.setStorageSync('cardNumber', eRes.data.cardNumber)
uni.setStorageSync('expiresTime', eRes.data.expiresTime)
}
})
// xuchao: 清除地址栏 token,防止分享泄露
this.clearUrlToken()
} else {
this.degradeToPhoneLogin()
}
}).catch(() => {
this.degradeToPhoneLogin()
})
},
// xuchao: 解码失败兜底,提示并跳手机号登录
degradeToPhoneLogin() {
uni.showToast({ title: '登录凭证已失效,请使用手机号登录', icon: 'none' })
setTimeout(() => {
uni.navigateTo({ url: '/pages/index/login' })
}, 800)
},
// xuchao: 从 URL hash 中移除 token 参数
clearUrlToken() {
try {
const hash = window.location.hash || ''
const qIndex = hash.indexOf('?')
if (qIndex === -1) return
const params = new URLSearchParams(hash.substring(qIndex + 1))
if (!params.has('token')) return
params.delete('token')
const rest = params.toString()
const base = hash.substring(0, qIndex)
window.history.replaceState(null, '', rest ? `${base}?${rest}` : base)
} catch (e) {}
},
getLocation() {
import('@/common/location.js').then(module => {
module.default.getLocation().then(({ lng, lat }) => {
@@ -83,8 +129,10 @@
}
const isAuth = uni.getStorageSync('isAuth')
const hasWin = uni.getStorageSync('hasWin')
// xuchao: 最近发起过认证流程(含取消)时忽略旧认证缓存,一律回认证页
const authFlowStarted = uni.getStorageSync('authFlowStarted')
let status = 'auth'
if (isAuth) {
if (isAuth && !authFlowStarted) {
status = hasWin ? 'info' : 'noWin'
}
uni.navigateTo({ url: `/pages/rights/rights?status=${status}` })