fix: 云闪付免密登录期间先清身份并遮罩占位,堵住换人窗口期的串号
云闪付入口带 token 进来时,tokenDecode 在途的几百毫秒里本机缓存仍是上一个账号的 phone/isAuth/cardNumber,而权益页只在 onLoad 取一次账号快照、不会自我纠正 —— 用户此时点进权益包会看到别人的权益数据。 1) 清缓存提前到发请求之前,窗口期最多读到未登录,读不到别人的数据;2) 解码期间 showLoading(mask) 占位并给 goRights 加在途拦截;3) 10s 看门狗 + onUnload 收尾,网络异常不会把遮罩卡死。
This commit is contained in:
+37
-6
@@ -58,23 +58,40 @@
|
||||
bg: 'https://aliyunoss.hn12301.net/hhrs/hhrs_syzn.png',
|
||||
url: '/pages/guide/use'
|
||||
}
|
||||
]
|
||||
],
|
||||
// xuchao: 云闪付免密登录是否仍在进行中 —— 返回前不放行任何依赖身份的跳转
|
||||
tokenLoginPending: false,
|
||||
tokenLoginTimer: null
|
||||
}
|
||||
},
|
||||
onLoad(options) {
|
||||
// xuchao: 云闪付入口带 token 进来 —— 直接免密换取会话,不经过手机号验证码
|
||||
if (options.token) {
|
||||
this.handleTokenLogin(options.token)
|
||||
}
|
||||
this.getLocation()
|
||||
},
|
||||
// xuchao: 离开首页时收尾,避免看门狗与遮罩残留
|
||||
onUnload() {
|
||||
this.finishTokenLogin()
|
||||
},
|
||||
methods: {
|
||||
// xuchao: 云闪付入口 token 自动登录
|
||||
// xuchao: 云闪付入口 token 自动登录(免密换人)
|
||||
handleTokenLogin(token) {
|
||||
this.$u.api.tokenDecode({ token }).then(res => {
|
||||
if (res.errcode === 0 && res.data && res.data.mobile) {
|
||||
// xuchao: 云闪付入口是“免密换人”,先丢弃本机上一个账号的会话与权益缓存,
|
||||
// 否则请求仍带旧 accessToken,后端“会话优先”会把上一个账号的数据返回给这位用户
|
||||
// xuchao: 云闪付入口是"免密换人",本机上一个账号的会话与权益缓存必须先丢弃:
|
||||
// 一是请求不能再带旧 accessToken(后端"会话优先"会把旧账号数据返给新用户),
|
||||
// 二是权益页只在 onLoad 取一次账号快照、不会自我纠正,所以清缓存必须赶在
|
||||
// 发请求之前 —— 解码返回前的窗口期里最多读到"未登录",绝不会读到别人的数据
|
||||
account.clearAccountCache()
|
||||
this.tokenLoginPending = true
|
||||
uni.showLoading({ title: '登录中', mask: true })
|
||||
// xuchao: 兜底看门狗,网络异常时不让遮罩卡死(只收遮罩,不改变登录结果)
|
||||
this.tokenLoginTimer = setTimeout(() => {
|
||||
this.finishTokenLogin()
|
||||
}, 10000)
|
||||
this.$u.api.tokenDecode({ token }).then(res => {
|
||||
this.finishTokenLogin()
|
||||
if (res.errcode === 0 && res.data && res.data.mobile) {
|
||||
uni.setStorageSync('phone', res.data.mobile)
|
||||
// xuchao: 后端已为云闪付入口签发会员会话,存下 accessToken,后续接口才认得这个用户
|
||||
if (res.data.accessToken) uni.setStorageSync('token', res.data.accessToken)
|
||||
@@ -92,9 +109,18 @@
|
||||
this.degradeToPhoneLogin()
|
||||
}
|
||||
}).catch(() => {
|
||||
this.finishTokenLogin()
|
||||
this.degradeToPhoneLogin()
|
||||
})
|
||||
},
|
||||
// xuchao: 免密登录收尾(收起遮罩、撤看门狗),成功/失败/超时/离开页面都会走到
|
||||
finishTokenLogin() {
|
||||
if (!this.tokenLoginPending) return
|
||||
this.tokenLoginPending = false
|
||||
clearTimeout(this.tokenLoginTimer)
|
||||
this.tokenLoginTimer = null
|
||||
uni.hideLoading()
|
||||
},
|
||||
// xuchao: 解码失败兜底,提示并跳手机号登录
|
||||
degradeToPhoneLogin() {
|
||||
uni.showToast({ title: '登录凭证已失效,请使用手机号登录', icon: 'none' })
|
||||
@@ -129,6 +155,11 @@
|
||||
uni.navigateTo({ url })
|
||||
},
|
||||
goRights() {
|
||||
// xuchao: 免密登录还没返回时不放行,避免带着空/旧身份进权益页
|
||||
if (this.tokenLoginPending) {
|
||||
uni.showToast({ title: '正在登录,请稍候', icon: 'none' })
|
||||
return
|
||||
}
|
||||
const phone = uni.getStorageSync('phone')
|
||||
if (!phone) {
|
||||
uni.navigateTo({ url: '/pages/index/login?redirect=rights' })
|
||||
|
||||
Reference in New Issue
Block a user