## 阻断性缺陷 - list.vue 是 0 字节空文件、slist.vue 与 search/search.vue 从未存在, 而前者是 tabBar 首页、后者是 tabBar「搜索」页 —— 开屏即白屏。 按 .nvue 原型与详情页契约重建三页(CSS 渐变主视觉、分类筛选、搜索历史/热搜/联想)。 - parse-image-url.js 对空封面调 undefined.startsWith 直接抛错,列表页整页崩。 - 云函数目录缺 uni-cms-articles / uni-cms-categories / uni-cms-unlock-record schema 与 schema.ext.js,线上内容渲染与解锁逻辑无配置可用。 ## 越权与数据一致性 - uni-cms-articles:del/update/add 全部无鉴权,未登录即可删任意文章、 改他人文章作者与阅读量。补 login + 作者归属校验,作者与计数改为服务端取值。 - comments.likeComment/relikeComment:直接采信客户端传入的 user_id, 可冒名点赞刷计数。改为以令牌为准,并纳入事务。 - comments.updateComment:对数组取 .author_id,权限判断恒失败; 字段名 updateTime 与 ip_location 类型与 schema 不符。 - comments.deleteComment:`!root_id === 0` 优先级错误导致计数恒不减; 且误更新 uni-cms-articles、按不存在的 type 字段删点赞明细产生孤儿数据。 - cms-articles-like/collect:查重条件混入本次请求时间戳,防重永远失效, 可无限重复刷计数;补唯一索引并事务化。 - cms-vote:读-改-写票数导致并发丢票,记录与统计非原子;改为事务 + 原子自增。 - cms-articles-log:忽略传入 user_id 直接返回全表,泄露全站浏览记录。 - article_info:get() 使用未定义变量必崩;读接口全部无鉴权。 - user-info:公开资料接口可查任意用户 last_login_ip。 ## 资源与数据 - 全项目清空失效的签名外链(expire_at 均为 2025-03,必然 403), 改为本地生成资源:6 套文章模板、8 个编辑器图标、2 张文章配图。 - 新增分类 / 模板 / 礼物 / 热搜词种子数据,并在 db_init.json 登记, 同时补上点赞、收藏、投票、浏览日志的唯一索引。 ## 功能 - 草稿箱:预览页拆出「发布」与「存为草稿」,作品列表按状态筛选并显示徽标。 原实现有 4 个 tab 但只有 1 个有内容,且 article_status 在 UI 上无体现。 - 编辑中断恢复:接上原本空实现的「编辑草稿」回调,区分新建与编辑已有文章。 ## 工具 - tools/audit-project.js:编码 / 页面路由 / 云调用 / 云函数鉴权 / 敏感信息检查 - tools/check-vue.js:SFC 脚本语法(词法扫描处理 import·export 与条件编译) - tools/verify.js:一键验证;两个检查器各带自测,防止"永远通过" - tools/gen-*.py:模板与图标资源生成脚本
151 lines
3.1 KiB
Vue
151 lines
3.1 KiB
Vue
<template>
|
||
<view class="short-code-btn" hover-class="hover" @click="start">
|
||
<text class="inner-text" :class="reverseNumber==0?'inner-text-active':''">{{innerText}}</text>
|
||
</view>
|
||
</template>
|
||
|
||
<script>
|
||
function debounce(func, wait) {
|
||
let timer;
|
||
wait = wait || 500;
|
||
return function() {
|
||
let context = this;
|
||
let args = arguments;
|
||
if (timer) clearTimeout(timer);
|
||
let callNow = !timer;
|
||
timer = setTimeout(() => {
|
||
timer = null;
|
||
}, wait)
|
||
if (callNow) func.apply(context, args);
|
||
}
|
||
}
|
||
export default {
|
||
name: "uni-send-sms-code",
|
||
props: {
|
||
/**
|
||
* 倒计时时长 s
|
||
*/
|
||
count: {
|
||
type: [String, Number],
|
||
default: 60
|
||
},
|
||
/**
|
||
* 手机号码
|
||
*/
|
||
phone: {
|
||
type: [String, Number],
|
||
default: ''
|
||
},
|
||
/*
|
||
验证码类型,用于防止不同功能的验证码混用,目前支持的类型login登录、register注册、bind绑定手机、unbind解绑手机
|
||
*/
|
||
codeType:{
|
||
type: String,
|
||
default(){
|
||
return 'login'
|
||
}
|
||
},
|
||
/**
|
||
* uni-id 短信场景,取值 login-by-sms / reset-pwd-by-sms / bind-mobile-by-sms / set-pwd-by-sms
|
||
*/
|
||
scene:{
|
||
type: String,
|
||
default(){
|
||
return 'login-by-sms'
|
||
}
|
||
},
|
||
/**
|
||
* 图形验证码;服务端要求图形验证码校验时必传
|
||
*/
|
||
captcha:{
|
||
type: String,
|
||
default(){
|
||
return ''
|
||
}
|
||
}
|
||
},
|
||
data() {
|
||
return {
|
||
reverseNumber: 0,
|
||
reverseTimer: null
|
||
};
|
||
},
|
||
computed: {
|
||
innerText() {
|
||
if (this.reverseNumber == 0) return '获取验证码';
|
||
return this.reverseNumber + 's后获取';
|
||
}
|
||
},
|
||
created() {
|
||
this.initClick();
|
||
},
|
||
methods: {
|
||
initClick() {
|
||
this.start = debounce(() => {
|
||
if (this.reverseNumber != 0) return;
|
||
this.sendMsg();
|
||
})
|
||
},
|
||
async sendMsg() {
|
||
let reg_phone = /^1\d{10}$/;
|
||
if(!reg_phone.test(this.phone))return uni.showToast({
|
||
title: '手机号格式错误',
|
||
icon: 'none'
|
||
});
|
||
try {
|
||
const uniIdCo = uniCloud.importObject('uni-id-co')
|
||
// scene 用 uni-id 的短信场景常量,与 codeType(login/register/bind)区分开
|
||
await uniIdCo.sendSmsCode({
|
||
mobile: String(this.phone),
|
||
scene: this.scene,
|
||
captcha: this.captcha
|
||
});
|
||
uni.showToast({
|
||
title: "短信验证码发送成功",
|
||
icon: 'none'
|
||
});
|
||
this.reverseNumber = Number(this.count);
|
||
this.getCode();
|
||
this.$emit('getCode');
|
||
} catch (e) {
|
||
console.error('短信验证码发送失败:', e);
|
||
uni.showToast({
|
||
title: e.errMsg || '发送失败,请稍后重试',
|
||
icon: 'none'
|
||
});
|
||
}
|
||
},
|
||
getCode() {
|
||
if (this.reverseNumber == 0) {
|
||
clearTimeout(this.reverseTimer);
|
||
this.reverseTimer = null;
|
||
return;
|
||
}
|
||
this.reverseNumber--;
|
||
this.reverseTimer = setTimeout(() => {
|
||
this.getCode();
|
||
}, 1000)
|
||
}
|
||
}
|
||
}
|
||
</script>
|
||
|
||
<style scoped lang="scss">
|
||
.short-code-btn {
|
||
width: 200rpx;
|
||
height: 85rpx;
|
||
/* #ifndef APP-NVUE */
|
||
display: flex;
|
||
/* #endif */
|
||
justify-content: center;
|
||
align-items: center;
|
||
}
|
||
.inner-text {
|
||
font-size: 26rpx;
|
||
color: #AAAAAA;
|
||
}
|
||
.inner-text-active {
|
||
color: #007aff;
|
||
}
|
||
</style>
|