fix: 云函数鉴权加固与投票数据防护
- follow/cms-vote/cms-articles-like/cms-articles-collect 云对象写操作强制 checkToken,uid 以服务端令牌为准,杜绝客户端伪造身份 - user-info.getIP 仅允许查询本人登录 IP(get_user_info 公开资料保持不变) - ext-storage-co 上传凭证需登录,删除文件仅限 admin 角色(原为完全裸奔) - cms-vote/cms-vote-info/user_select_vote 三表 schema 写权限全部关闭(投票读写均走云对象) - 修复 follow.reFollow 中 total<0 永假导致的逻辑错误 - 各云对象 package.json 补 uni-id-common 依赖声明 - main.js 登录过期跳转修正为实际页面路径 /pages/login/login
This commit is contained in:
@@ -1,10 +1,13 @@
|
||||
const { count } = require("console");
|
||||
const uniID = require('uni-id-common');
|
||||
|
||||
const db = uniCloud.database();
|
||||
const _ =db.command;
|
||||
module.exports = {
|
||||
_before: function () { // 通用预处理器
|
||||
|
||||
this.uniID = uniID.createInstance({
|
||||
context: this.getClientInfo()
|
||||
});
|
||||
},
|
||||
async getVoteInfo(query) {
|
||||
try {
|
||||
@@ -42,12 +45,15 @@ module.exports = {
|
||||
},
|
||||
async add_vote(query) {
|
||||
try {
|
||||
const payload = await this.uniID.checkToken(this.getUniIdToken());
|
||||
if (payload.errCode) throw new Error('登录状态失效,请重新登录');
|
||||
let {
|
||||
vote_id,
|
||||
selectValue,
|
||||
user_id,
|
||||
type
|
||||
} = query;
|
||||
user_id = payload.uid; // 以服务端令牌为准,忽略客户端传入
|
||||
|
||||
let t = await db.collection("cms-vote")
|
||||
.where({
|
||||
|
||||
Reference in New Issue
Block a user