fix: 只接受非空字符串凭证,防脏 accessToken 打挂鉴权;修正认证页提示文案

This commit is contained in:
jacobxu666
2026-09-15 12:42:36 +08:00
parent 1fe8c133ad
commit 6b1037893e
3 changed files with 10 additions and 6 deletions
+5 -2
View File
@@ -93,8 +93,11 @@
this.finishTokenLogin()
if (res.errcode === 0 && res.data && res.data.mobile) {
uni.setStorageSync('phone', res.data.mobile)
// xuchao: 后端已为云闪付入口签发会员会话,存下 accessToken,后续接口才认得这个用户
if (res.data.accessToken) uni.setStorageSync('token', res.data.accessToken)
// xuchao: 后端已为云闪付入口签发会员会话,存下 accessToken,后续接口才认得这个用户。
// 只认"非空字符串":后端字段缺失/为 null 时会被序列化成 {},直接存进缓存
// 就会变成 Bearer [object Object],把所有鉴权接口全打挂
const issued = typeof res.data.accessToken === 'string' ? res.data.accessToken : ''
if (issued) uni.setStorageSync('token', issued)
this.$u.api.getEligibility({ phone: res.data.mobile, identityNo: res.data.idNo || '', name: res.data.name || '' }).then(eRes => {
if (eRes.errcode === 0) {
uni.setStorageSync('isAuth', eRes.data.isAuth)
+4 -3
View File
@@ -125,10 +125,11 @@ export default {
// xuchao: password 为后端要求的固定旁路口令,集中取自 config.loginFixedPassword
this.$u.api.checkerLogin({ password: config.loginFixedPassword, mobile: this.phone, verifyCode: this.code }).then(res => {
if (this.isBizOk(res)) {
// xuchao: 后端当前只回 userId/userName,并未下发 accessToken(字段名也是 accessToken)。
// 取到才存、取不到存空串,避免把 undefined 写进 storage 变成 "Bearer undefined"
// xuchao: 只认"非空字符串"凭证。后端若把 null 序列化成 {}(实测 tokenDecode 就是这个形状),
// 用 || 兜底会把对象存进缓存,之后每个请求都变成 Bearer [object Object]
const payload = (res.data && res.data.data) || {}
uni.setStorageSync('token', payload.accessToken || payload.token || '')
const issued = [payload.accessToken, payload.token].find(v => typeof v === 'string' && v.length > 0)
uni.setStorageSync('token', issued || '')
uni.setStorageSync('phone', this.phone)
this.$u.api.getEligibility({ phone: this.phone, identityNo: '', name: '' }).then(eRes => {
if (eRes.errcode === 0) {
+1 -1
View File
@@ -46,7 +46,7 @@
<view class="tips-list">
<text class="tip-item">1. 请输入真实的身份信息用来进行活动权益资格认证</text>
<text class="tip-item">2. 认证通过后系统会显示出您的所获得的权益信息</text>
<text class="tip-item">3. 手机号码为您登录的手机,无法修改。若号码对,请更换登录手机。</text>
<text class="tip-item">3. 手机号码为您登录的手机号,无法修改。若号码不对,请更换手机号重新登录。</text>
</view>
</view>
</view>