fix: 只接受非空字符串凭证,防脏 accessToken 打挂鉴权;修正认证页提示文案
This commit is contained in:
@@ -93,8 +93,11 @@
|
||||
this.finishTokenLogin()
|
||||
if (res.errcode === 0 && res.data && res.data.mobile) {
|
||||
uni.setStorageSync('phone', res.data.mobile)
|
||||
// xuchao: 后端已为云闪付入口签发会员会话,存下 accessToken,后续接口才认得这个用户
|
||||
if (res.data.accessToken) uni.setStorageSync('token', res.data.accessToken)
|
||||
// xuchao: 后端已为云闪付入口签发会员会话,存下 accessToken,后续接口才认得这个用户。
|
||||
// 只认"非空字符串":后端字段缺失/为 null 时会被序列化成 {},直接存进缓存
|
||||
// 就会变成 Bearer [object Object],把所有鉴权接口全打挂
|
||||
const issued = typeof res.data.accessToken === 'string' ? res.data.accessToken : ''
|
||||
if (issued) uni.setStorageSync('token', issued)
|
||||
this.$u.api.getEligibility({ phone: res.data.mobile, identityNo: res.data.idNo || '', name: res.data.name || '' }).then(eRes => {
|
||||
if (eRes.errcode === 0) {
|
||||
uni.setStorageSync('isAuth', eRes.data.isAuth)
|
||||
|
||||
@@ -125,10 +125,11 @@ export default {
|
||||
// xuchao: password 为后端要求的固定旁路口令,集中取自 config.loginFixedPassword
|
||||
this.$u.api.checkerLogin({ password: config.loginFixedPassword, mobile: this.phone, verifyCode: this.code }).then(res => {
|
||||
if (this.isBizOk(res)) {
|
||||
// xuchao: 后端当前只回 userId/userName,并未下发 accessToken(字段名也是 accessToken)。
|
||||
// 取到才存、取不到存空串,避免把 undefined 写进 storage 变成 "Bearer undefined"
|
||||
// xuchao: 只认"非空字符串"凭证。后端若把 null 序列化成 {}(实测 tokenDecode 就是这个形状),
|
||||
// 用 || 兜底会把对象存进缓存,之后每个请求都变成 Bearer [object Object]
|
||||
const payload = (res.data && res.data.data) || {}
|
||||
uni.setStorageSync('token', payload.accessToken || payload.token || '')
|
||||
const issued = [payload.accessToken, payload.token].find(v => typeof v === 'string' && v.length > 0)
|
||||
uni.setStorageSync('token', issued || '')
|
||||
uni.setStorageSync('phone', this.phone)
|
||||
this.$u.api.getEligibility({ phone: this.phone, identityNo: '', name: '' }).then(eRes => {
|
||||
if (eRes.errcode === 0) {
|
||||
|
||||
@@ -46,7 +46,7 @@
|
||||
<view class="tips-list">
|
||||
<text class="tip-item">1. 请输入真实的身份信息用来进行活动权益资格认证</text>
|
||||
<text class="tip-item">2. 认证通过后系统会显示出您的所获得的权益信息</text>
|
||||
<text class="tip-item">3. 手机号码为您登录的手机,无法修改。若号码对,请更换登录手机。</text>
|
||||
<text class="tip-item">3. 手机号码为您登录的手机号,无法修改。若号码不对,请更换手机号重新登录。</text>
|
||||
</view>
|
||||
</view>
|
||||
</view>
|
||||
|
||||
Reference in New Issue
Block a user