Compare commits

...

2 Commits

Author SHA1 Message Date
kk b2b92ec6b4 防止重复跳转
Uni-app H5 Deploy (Prod + Staging) / deploy (release) Successful in 45s
2026-07-17 15:13:13 +08:00
kk b336b901d3 前端传入state
Uni-app H5 Deploy (Prod + Staging) / deploy (release) Successful in 48s
2026-07-17 14:40:21 +08:00
2 changed files with 66 additions and 51 deletions
+51 -30
View File
@@ -16,6 +16,7 @@ export default {
statusText: '正在登录...', statusText: '正在登录...',
deviceId: '', deviceId: '',
action: '', action: '',
navigating: false, // 防止重复跳转
}; };
}, },
onLoad(options) { onLoad(options) {
@@ -91,6 +92,13 @@ export default {
* 发起 OAuth 授权(静默授权,只获取 openid) * 发起 OAuth 授权(静默授权,只获取 openid)
*/ */
async startAuth() { async startAuth() {
// 防止重复调用
if (this.navigating) {
console.log('[Auth] 已在跳转中,忽略重复 startAuth');
return;
}
this.navigating = true;
// 清除上次使用的 code 标记 // 清除上次使用的 code 标记
uni.removeStorageSync('__used_auth_code'); uni.removeStorageSync('__used_auth_code');
@@ -118,28 +126,24 @@ export default {
// 静默授权:微信用 snsapi_base,支付宝用 auth_base // 静默授权:微信用 snsapi_base,支付宝用 auth_base
const scopes = platform === 'alipay' ? 'auth_base' : 'snsapi_base'; const scopes = platform === 'alipay' ? 'auth_base' : 'snsapi_base';
// 构建 state(包含 device_id,回调时原样回传)
const stateObj = {};
if (this.deviceId) {
stateObj.device_id = this.deviceId;
}
const res = await gatewayGet('/api/v1/user/auth/url', { const res = await gatewayGet('/api/v1/user/auth/url', {
app_no: appNo, app_no: appNo,
scopes: scopes, scopes: scopes,
redirect_uri: redirectUri, redirect_uri: redirectUri,
state: Object.keys(stateObj).length > 0 ? JSON.stringify(stateObj) : '',
}); });
const data = res.data || {}; const data = res.data || {};
if (data.code === 0 && data.data && data.data.auth_url) { if (data.code === 0 && data.data && data.data.auth_url) {
// 通过 state 传递 device_idOAuth 标准保证 state 原样回传) // 后端已将 state 写入授权 URL,直接跳转
let authUrl = data.data.auth_url; window.location.href = data.data.auth_url;
if (this.deviceId) {
const stateVal = encodeURIComponent(JSON.stringify({ device_id: this.deviceId }));
try {
const urlObj = new URL(authUrl);
urlObj.searchParams.set('state', stateVal);
authUrl = urlObj.toString();
} catch (_) {
authUrl += (authUrl.includes('?') ? '&' : '?') + 'state=' + stateVal;
}
}
// 跳转微信授权页(静默,不弹窗)
window.location.href = authUrl;
} else { } else {
uni.showToast({ title: data.message || '获取授权失败', icon: 'none' }); uni.showToast({ title: data.message || '获取授权失败', icon: 'none' });
setTimeout(() => this.goToScan(), 1500); setTimeout(() => this.goToScan(), 1500);
@@ -155,6 +159,13 @@ export default {
* 处理授权回调(用 code 换 openid,再用 openid 登录) * 处理授权回调(用 code 换 openid,再用 openid 登录)
*/ */
async handleCallback(code) { async handleCallback(code) {
// 防止重复调用(redirectTo 是异步的,页面可能被重新触发)
if (this.navigating) {
console.log('[Auth] 已在跳转中,忽略重复 handleCallback');
return;
}
this.navigating = true;
const appNo = uni.getStorageSync('app_no') || getAppNo(detectPlatform()); const appNo = uni.getStorageSync('app_no') || getAppNo(detectPlatform());
if (!appNo) { if (!appNo) {
@@ -167,6 +178,7 @@ export default {
const usedCode = uni.getStorageSync('__used_auth_code'); const usedCode = uni.getStorageSync('__used_auth_code');
if (usedCode === code) { if (usedCode === code) {
console.warn('[loading] code 已使用过,跳过'); console.warn('[loading] code 已使用过,跳过');
this.navigating = false;
return; return;
} }
uni.setStorageSync('__used_auth_code', code); uni.setStorageSync('__used_auth_code', code);
@@ -251,6 +263,13 @@ export default {
* 发起非静默授权获取用户信息(snsapi_userinfo,弹窗确认) * 发起非静默授权获取用户信息(snsapi_userinfo,弹窗确认)
*/ */
async startUserInfoAuth() { async startUserInfoAuth() {
// 防止重复调用
if (this.navigating) {
console.log('[Auth] 已在跳转中,忽略重复 startUserInfoAuth');
return;
}
this.navigating = true;
// 清除上次使用的 code 标记 // 清除上次使用的 code 标记
uni.removeStorageSync('__used_auth_code'); uni.removeStorageSync('__used_auth_code');
@@ -279,30 +298,24 @@ export default {
// 用户信息授权:微信用 snsapi_userinfo,支付宝用 auth_user // 用户信息授权:微信用 snsapi_userinfo,支付宝用 auth_user
const scopes = platform === 'alipay' ? 'auth_user' : 'snsapi_userinfo'; const scopes = platform === 'alipay' ? 'auth_user' : 'snsapi_userinfo';
// 构建 state(包含 action 和 device_id,回调时原样回传)
const stateObj = { action: 'userinfo' };
if (this.deviceId) {
stateObj.device_id = this.deviceId;
}
const res = await gatewayGet('/api/v1/user/auth/url', { const res = await gatewayGet('/api/v1/user/auth/url', {
app_no: appNo, app_no: appNo,
scopes: scopes, scopes: scopes,
redirect_uri: redirectUri, redirect_uri: redirectUri,
state: JSON.stringify(stateObj),
}); });
const data = res.data || {}; const data = res.data || {};
if (data.code === 0 && data.data && data.data.auth_url) { if (data.code === 0 && data.data && data.data.auth_url) {
// 通过 state 传递 action 和 device_idOAuth 标准保证 state 原样回传) // 后端已将 state 写入授权 URL,直接跳转
const stateObj = { action: 'userinfo' }; window.location.href = data.data.auth_url;
if (this.deviceId) {
stateObj.device_id = this.deviceId;
}
const stateVal = encodeURIComponent(JSON.stringify(stateObj));
let authUrl = data.data.auth_url;
try {
const urlObj = new URL(authUrl);
urlObj.searchParams.set('state', stateVal);
authUrl = urlObj.toString();
} catch (_) {
authUrl += (authUrl.includes('?') ? '&' : '?') + 'state=' + stateVal;
}
// 跳转微信授权页(弹窗确认)
window.location.href = authUrl;
} else { } else {
uni.showToast({ title: data.message || '获取授权失败', icon: 'none' }); uni.showToast({ title: data.message || '获取授权失败', icon: 'none' });
setTimeout(() => this.goToHomeWithAction(), 1500); setTimeout(() => this.goToHomeWithAction(), 1500);
@@ -318,6 +331,13 @@ export default {
* 处理用户信息授权回调(用 code 调 /api/v1/user/info 获取头像昵称) * 处理用户信息授权回调(用 code 调 /api/v1/user/info 获取头像昵称)
*/ */
async handleUserInfoCallback(code) { async handleUserInfoCallback(code) {
// 防止重复调用
if (this.navigating) {
console.log('[Auth] 已在跳转中,忽略重复 handleUserInfoCallback');
return;
}
this.navigating = true;
const appNo = uni.getStorageSync('app_no') || getAppNo(detectPlatform()); const appNo = uni.getStorageSync('app_no') || getAppNo(detectPlatform());
if (!appNo) { if (!appNo) {
@@ -329,6 +349,7 @@ export default {
const usedCode = uni.getStorageSync('__used_auth_code'); const usedCode = uni.getStorageSync('__used_auth_code');
if (usedCode === code) { if (usedCode === code) {
console.warn('[loading] code 已使用过,跳过'); console.warn('[loading] code 已使用过,跳过');
this.navigating = false;
return; return;
} }
uni.setStorageSync('__used_auth_code', code); uni.setStorageSync('__used_auth_code', code);
+15 -21
View File
@@ -344,34 +344,28 @@ export default {
window.location.origin.replace(/^http:/, 'https:') + window.location.pathname window.location.origin.replace(/^http:/, 'https:') + window.location.pathname
); );
// 获取非静默授权链接(会弹窗确认 // 构建 state(包含 action 和 device_id,回调时原样回传
const stateObj = { action: 'userinfo' };
if (this.deviceId) {
stateObj.device_id = this.deviceId;
}
// 用户信息授权:微信用 snsapi_userinfo,支付宝用 auth_user
const platform = uni.getStorageSync('platform') || 'wechat';
const scopes = platform === 'alipay' ? 'auth_user' : 'snsapi_userinfo';
const res = await gatewayGet('/api/v1/user/auth/url', { const res = await gatewayGet('/api/v1/user/auth/url', {
app_no: appNo, app_no: appNo,
scopes: 'snsapi_userinfo', scopes: scopes,
redirect_uri: redirectUri, redirect_uri: redirectUri,
state: JSON.stringify(stateObj),
}); });
const data = res.data || {}; const data = res.data || {};
if (data.code === 0 && data.data && data.data.auth_url) { if (data.code === 0 && data.data && data.data.auth_url) {
// 通过 state 传递 action 和 device_idOAuth 标准保证 state 原样回传) console.log('[index] 跳转授权页:', data.data.auth_url);
const stateObj = { action: 'userinfo' }; // 后端已将 state 写入授权 URL,直接跳转
if (this.deviceId) { window.location.href = data.data.auth_url;
stateObj.device_id = this.deviceId;
}
const stateVal = encodeURIComponent(JSON.stringify(stateObj));
// 解析 auth_url,安全地设置 state 参数(避免重复)
let authUrl = data.data.auth_url;
try {
const urlObj = new URL(authUrl);
urlObj.searchParams.set('state', stateVal);
authUrl = urlObj.toString();
} catch (_) {
// URL 解析失败时直接拼接
authUrl += (authUrl.includes('?') ? '&' : '?') + 'state=' + stateVal;
}
console.log('[index] 跳转授权页:', authUrl);
// 跳转微信授权页(弹窗确认)
window.location.href = authUrl;
} else { } else {
console.warn('[index] 获取授权链接失败:', data.message); console.warn('[index] 获取授权链接失败:', data.message);
} }