fix: 修复登录失败被当成功、列表假分页与首页裁切等隐患

1. 登录/验证码改判业务码 data.code(外层 errcode 恒为0),失败不再写入 phone 造成假登录态,并透出后端真实原因;倒计时改为发送成功后才启动;token 按 accessToken 兜底读取,不再写入 undefined

2. 权益包三 Tab 由 pageSize=1000 的假分页改为真实分页 + 页面级触底加载,各 Tab 独立游标与请求序号,合并去重兜底;中奖名单页码改为按期维护,修复切期后重复追加

3. 首页去掉整页 overflow:hidden,小屏不再裁切活动指南卡片;接口表去重并清理 7 个废弃端点;基址/客服电话集中到 common/config.js;删除权益详情不可达的假成功分支
This commit is contained in:
jacobxu666
2026-09-14 23:38:13 +08:00
parent 4e72e81d47
commit 745f4bf5f1
8 changed files with 279 additions and 255 deletions
+3 -8
View File
@@ -142,15 +142,11 @@
</script>
<style>
page {
height: 100%;
overflow: hidden;
}
/* xuchao: 原 page/.page 固定 100vh + overflow:hidden,小屏下活动指南第二张卡片会被裁掉且无法滚动;
改为 min-height 撑满、超出可滚动,视觉在正常屏上保持不变 */
.page {
height: 100vh;
min-height: 100vh;
background-color: #f5f5f5;
overflow: hidden;
display: flex;
flex-direction: column;
}
@@ -196,7 +192,6 @@
flex: 1;
background-color: #ffffff;
margin-top: 10rpx;
overflow: hidden;
display: flex;
flex-direction: column;
}
+37 -14
View File
@@ -43,6 +43,8 @@
</template>
<script>
import config from '@/common/config.js'
export default {
data() {
return {
@@ -63,6 +65,19 @@ export default {
}
},
methods: {
// xuchao: open-api/pingXiang/login、sendLoginVerifyCode 返回 OpenapiResponse{code,msg,data},
// 被网关再包一层后外层 errcode 恒为 0,真正的业务码在 data.code 里。
// 只判 errcode 会把「验证码错误/过期、短信被限流」全部当成成功。
// 宽松兜底:后端若改成不返回 data.code,仍按 errcode 判定,不会把成功误判为失败。
isBizOk(res) {
if (!res || res.errcode !== 0) return false
const d = res.data
return !d || d.code === undefined || d.code === null || d.code === 200
},
// xuchao: 失败原因优先取业务 msg,其次取网关 errmsg
bizMsg(res) {
return (res && res.data && res.data.msg) || (res && res.errmsg) || ''
},
sendCode() {
if (this.countdown > 0) return
if (!this.phone || !/^1\d{10}$/.test(this.phone)) {
@@ -70,22 +85,24 @@ export default {
return
}
this.$u.api.sendLoginVerifyCode({ smsType: 'CIB_LOGIN', mobile: this.phone }).then(res => {
if (res.errcode === 0) {
if (this.isBizOk(res)) {
uni.showToast({ title: '验证码已发送', icon: 'success' })
// xuchao: 倒计时移到发送成功之后(原来无条件启动,发送失败也会被白锁 60 秒无法重试)
this.countdown = 60
this.timer = setInterval(() => {
this.countdown--
if (this.countdown <= 0) {
clearInterval(this.timer)
this.timer = null
}
}, 1000)
} else {
uni.showToast({ title: res.errmsg || '发送失败', icon: 'none' })
// xuchao: 透出后端真实原因,如「操作频繁,请稍后再试」
uni.showToast({ title: this.bizMsg(res) || '发送失败', icon: 'none' })
}
}).catch(() => {
uni.showToast({ title: '发送失败', icon: 'none' })
})
this.countdown = 60
this.timer = setInterval(() => {
this.countdown--
if (this.countdown <= 0) {
clearInterval(this.timer)
this.timer = null
}
}, 1000)
},
onLogin() {
if (!this.phone || !/^1\d{10}$/.test(this.phone)) {
@@ -100,9 +117,13 @@ export default {
uni.showToast({ title: '请同意用户协议和隐私协议', icon: 'none' })
return
}
this.$u.api.checkerLogin({ password: '1232321', mobile: this.phone, verifyCode: this.code }).then(res => {
if (res.errcode === 0) {
uni.setStorageSync('token', res.data.token)
// xuchao: password 为后端要求的固定旁路口令,集中取自 config.loginFixedPassword
this.$u.api.checkerLogin({ password: config.loginFixedPassword, mobile: this.phone, verifyCode: this.code }).then(res => {
if (this.isBizOk(res)) {
// xuchao: 后端当前只回 userId/userName,并未下发 accessToken(字段名也是 accessToken)。
// 取到才存、取不到存空串,避免把 undefined 写进 storage 变成 "Bearer undefined"
const payload = (res.data && res.data.data) || {}
uni.setStorageSync('token', payload.accessToken || payload.token || '')
uni.setStorageSync('phone', this.phone)
this.$u.api.getEligibility({ phone: this.phone, identityNo: '', name: '' }).then(eRes => {
if (eRes.errcode === 0) {
@@ -125,7 +146,9 @@ export default {
}
})
} else {
uni.showToast({ title: res.errmsg || '登录失败', icon: 'none' })
// xuchao: 透出后端真实原因,如「验证码错误」「验证码已过期,请重新获取」;
// 失败时绝不写 phone,避免留下“假登录态”让后续页面以为已登录
uni.showToast({ title: this.bizMsg(res) || '登录失败', icon: 'none' })
}
}).catch(() => {
uni.showToast({ title: '登录失败', icon: 'none' })