fix: 只接受非空字符串凭证,防脏 accessToken 打挂鉴权;修正认证页提示文案

This commit is contained in:
jacobxu666
2026-09-15 12:42:36 +08:00
parent 1fe8c133ad
commit 6b1037893e
3 changed files with 10 additions and 6 deletions
+4 -3
View File
@@ -125,10 +125,11 @@ export default {
// xuchao: password 为后端要求的固定旁路口令,集中取自 config.loginFixedPassword
this.$u.api.checkerLogin({ password: config.loginFixedPassword, mobile: this.phone, verifyCode: this.code }).then(res => {
if (this.isBizOk(res)) {
// xuchao: 后端当前只回 userId/userName,并未下发 accessToken(字段名也是 accessToken)。
// 取到才存、取不到存空串,避免把 undefined 写进 storage 变成 "Bearer undefined"
// xuchao: 只认"非空字符串"凭证。后端若把 null 序列化成 {}(实测 tokenDecode 就是这个形状),
// 用 || 兜底会把对象存进缓存,之后每个请求都变成 Bearer [object Object]
const payload = (res.data && res.data.data) || {}
uni.setStorageSync('token', payload.accessToken || payload.token || '')
const issued = [payload.accessToken, payload.token].find(v => typeof v === 'string' && v.length > 0)
uni.setStorageSync('token', issued || '')
uni.setStorageSync('phone', this.phone)
this.$u.api.getEligibility({ phone: this.phone, identityNo: '', name: '' }).then(eRes => {
if (eRes.errcode === 0) {