refactor: 登录改用 hhrs 专属接口地址,并收紧成功判定防假成功

1. http.api.js 登录/验证码地址切到 open-api/hhService/login、open-api/hhService/sendLoginVerifyCode(后端保留 /pingXiang 旧地址转发,旧包不受影响;新包需后端先部署)

2. isBizOk 收紧:无业务码时额外排除网关把 404/错误页包成 HTTP 200 的情况(实测未部署的新地址会返回 {data:{status:404,error:'Not Found'}} 且 errcode=0),避免又被判成成功

验证:7 组判定用例全通过(含 404 包 200、旧后端无 accessToken 等边界);HBuilderX 编译成功;浏览器实测新地址未部署时提示“登录失败”且不写入登录态,其余页面正常、无 JS 错误。
This commit is contained in:
jacobxu666
2026-09-15 10:24:50 +08:00
parent a53b228f0b
commit e836fb33c8
3 changed files with 11 additions and 5 deletions
+7 -2
View File
@@ -65,14 +65,19 @@ export default {
}
},
methods: {
// xuchao: open-api/pingXiang/login、sendLoginVerifyCode 返回 OpenapiResponse{code,msg,data},
// xuchao: open-api/hhService/login、sendLoginVerifyCode 返回 OpenapiResponse{code,msg,data},
// 被网关再包一层后外层 errcode 恒为 0,真正的业务码在 data.code 里。
// 只判 errcode 会把「验证码错误/过期、短信被限流」全部当成成功。
// 宽松兜底:后端若改成不返回 data.code,仍按 errcode 判定,不会把成功误判为失败。
isBizOk(res) {
if (!res || res.errcode !== 0) return false
const d = res.data
return !d || d.code === undefined || d.code === null || d.code === 200
if (!d || d.code === undefined || d.code === null) {
// xuchao: 没有业务码时,还要排除“网关把 404/错误页包成 HTTP 200”的情况
// (实测未部署的新地址会返回 {data:{timestamp,status:404,error:'Not Found'}} 且 errcode=0)
return !d || (d.status === undefined && d.error === undefined)
}
return d.code === 200
},
// xuchao: 失败原因优先取业务 msg,其次取网关 errmsg
bizMsg(res) {