refactor: 登录改用 hhrs 专属接口地址,并收紧成功判定防假成功

1. http.api.js 登录/验证码地址切到 open-api/hhService/login、open-api/hhService/sendLoginVerifyCode(后端保留 /pingXiang 旧地址转发,旧包不受影响;新包需后端先部署)

2. isBizOk 收紧:无业务码时额外排除网关把 404/错误页包成 HTTP 200 的情况(实测未部署的新地址会返回 {data:{status:404,error:'Not Found'}} 且 errcode=0),避免又被判成成功

验证:7 组判定用例全通过(含 404 包 200、旧后端无 accessToken 等边界);HBuilderX 编译成功;浏览器实测新地址未部署时提示“登录失败”且不写入登录态,其余页面正常、无 JS 错误。
This commit is contained in:
jacobxu666
2026-09-15 10:24:50 +08:00
parent a53b228f0b
commit e836fb33c8
3 changed files with 11 additions and 5 deletions
+1 -1
View File
@@ -4,7 +4,7 @@ const config = {
baseUrl: 'https://dscp-uat.hn12301.net',
// 对外统一客服电话,与《用户协议》《隐私协议》公示号码保持一致
servicePhone: '0731-88912301',
// xuchao: open-api/pingXiang/login 强制校验固定 password 字段(后端为 H5 开的旁路),
// xuchao: open-api/hhService/login 强制校验固定 password 字段(后端为 H5 开的旁路,
// 前端去掉即登录失败,故集中存放并在此说明;待后端改造 H5 免密登录后删除。
loginFixedPassword: '1232321'
}
+3 -2
View File
@@ -1,8 +1,9 @@
// xuchao: 怀化人社 H5 接口清单,与 docs/hhrs-api-doc.md 一一对应
// 基址由 common/http.interceptor.js 统一注入(common/config.js.baseUrl)
// 登录 / 云闪付入口
const LoginUrl = 'open-api/pingXiang/login'
const SendVerifyCodeUrl = 'open-api/pingXiang/sendLoginVerifyCode'
// xuchao: hhrs 专属登录端点(旧地址 open-api/pingXiang/* 由后端兼容层转发,已弃用)
const LoginUrl = 'open-api/hhService/login'
const SendVerifyCodeUrl = 'open-api/hhService/sendLoginVerifyCode'
const TokenDecodeUrl = 'open-api/hhService/tokenDecode'
// 门店(文旅场馆 typeId=1 / 商户折扣 typeId=2)
const StoreListUrl = 'mp-api/hhrsStore/list'
+7 -2
View File
@@ -65,14 +65,19 @@ export default {
}
},
methods: {
// xuchao: open-api/pingXiang/login、sendLoginVerifyCode 返回 OpenapiResponse{code,msg,data},
// xuchao: open-api/hhService/login、sendLoginVerifyCode 返回 OpenapiResponse{code,msg,data},
// 被网关再包一层后外层 errcode 恒为 0,真正的业务码在 data.code 里。
// 只判 errcode 会把「验证码错误/过期、短信被限流」全部当成成功。
// 宽松兜底:后端若改成不返回 data.code,仍按 errcode 判定,不会把成功误判为失败。
isBizOk(res) {
if (!res || res.errcode !== 0) return false
const d = res.data
return !d || d.code === undefined || d.code === null || d.code === 200
if (!d || d.code === undefined || d.code === null) {
// xuchao: 没有业务码时,还要排除“网关把 404/错误页包成 HTTP 200”的情况
// (实测未部署的新地址会返回 {data:{timestamp,status:404,error:'Not Found'}} 且 errcode=0)
return !d || (d.status === undefined && d.error === undefined)
}
return d.code === 200
},
// xuchao: 失败原因优先取业务 msg,其次取网关 errmsg
bizMsg(res) {