fix: 云闪付免密登录期间先清身份并遮罩占位,堵住换人窗口期的串号

云闪付入口带 token 进来时,tokenDecode 在途的几百毫秒里本机缓存仍是上一个账号的 phone/isAuth/cardNumber,而权益页只在 onLoad 取一次账号快照、不会自我纠正 —— 用户此时点进权益包会看到别人的权益数据。

1) 清缓存提前到发请求之前,窗口期最多读到未登录,读不到别人的数据;2) 解码期间 showLoading(mask) 占位并给 goRights 加在途拦截;3) 10s 看门狗 + onUnload 收尾,网络异常不会把遮罩卡死。
This commit is contained in:
jacobxu666
2026-09-15 11:19:01 +08:00
parent c80eef5112
commit 1fe8c133ad
+37 -6
View File
@@ -58,23 +58,40 @@
bg: 'https://aliyunoss.hn12301.net/hhrs/hhrs_syzn.png',
url: '/pages/guide/use'
}
]
],
// xuchao: 云闪付免密登录是否仍在进行中 —— 返回前不放行任何依赖身份的跳转
tokenLoginPending: false,
tokenLoginTimer: null
}
},
onLoad(options) {
// xuchao: 云闪付入口带 token 进来 —— 直接免密换取会话,不经过手机号验证码
if (options.token) {
this.handleTokenLogin(options.token)
}
this.getLocation()
},
// xuchao: 离开首页时收尾,避免看门狗与遮罩残留
onUnload() {
this.finishTokenLogin()
},
methods: {
// xuchao: 云闪付入口 token 自动登录
// xuchao: 云闪付入口 token 自动登录(免密换人)
handleTokenLogin(token) {
this.$u.api.tokenDecode({ token }).then(res => {
if (res.errcode === 0 && res.data && res.data.mobile) {
// xuchao: 云闪付入口是“免密换人”,先丢弃本机上一个账号的会话与权益缓存,
// 否则请求仍带旧 accessToken,后端“会话优先”会把上一个账号的数据返回给这位用户
// xuchao: 云闪付入口是"免密换人",本机上一个账号的会话与权益缓存必须先丢弃:
// 一是请求不能再带旧 accessToken(后端"会话优先"会把旧账号数据返给新用户),
// 二是权益页只在 onLoad 取一次账号快照、不会自我纠正,所以清缓存必须赶在
// 发请求之前 —— 解码返回前的窗口期里最多读到"未登录",绝不会读到别人的数据
account.clearAccountCache()
this.tokenLoginPending = true
uni.showLoading({ title: '登录中', mask: true })
// xuchao: 兜底看门狗,网络异常时不让遮罩卡死(只收遮罩,不改变登录结果)
this.tokenLoginTimer = setTimeout(() => {
this.finishTokenLogin()
}, 10000)
this.$u.api.tokenDecode({ token }).then(res => {
this.finishTokenLogin()
if (res.errcode === 0 && res.data && res.data.mobile) {
uni.setStorageSync('phone', res.data.mobile)
// xuchao: 后端已为云闪付入口签发会员会话,存下 accessToken,后续接口才认得这个用户
if (res.data.accessToken) uni.setStorageSync('token', res.data.accessToken)
@@ -92,9 +109,18 @@
this.degradeToPhoneLogin()
}
}).catch(() => {
this.finishTokenLogin()
this.degradeToPhoneLogin()
})
},
// xuchao: 免密登录收尾(收起遮罩、撤看门狗),成功/失败/超时/离开页面都会走到
finishTokenLogin() {
if (!this.tokenLoginPending) return
this.tokenLoginPending = false
clearTimeout(this.tokenLoginTimer)
this.tokenLoginTimer = null
uni.hideLoading()
},
// xuchao: 解码失败兜底,提示并跳手机号登录
degradeToPhoneLogin() {
uni.showToast({ title: '登录凭证已失效,请使用手机号登录', icon: 'none' })
@@ -129,6 +155,11 @@
uni.navigateTo({ url })
},
goRights() {
// xuchao: 免密登录还没返回时不放行,避免带着空/旧身份进权益页
if (this.tokenLoginPending) {
uni.showToast({ title: '正在登录,请稍候', icon: 'none' })
return
}
const phone = uni.getStorageSync('phone')
if (!phone) {
uni.navigateTo({ url: '/pages/index/login?redirect=rights' })