mirror of
https://github.com/hansjone/oclaw.git
synced 2026-10-08 23:33:16 +08:00
Fix QR login: pass userSearchUrl into auth middleware for token+empNo verify.
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
b535714000
commit
74a86ff832
3 changed files with 54 additions and 10 deletions
|
|
@ -508,6 +508,25 @@ window.__ModuleLoader__.load({
|
|||
if (empNo && token) {
|
||||
setCookie('PORTALSSOUser', empNo, 7)
|
||||
setCookie('PORTALSSOCookie', token, 7)
|
||||
try {
|
||||
const info = await fetchJson(
|
||||
'/uds-auth/user-info?empNo=' + encodeURIComponent(empNo)
|
||||
+ '&token=' + encodeURIComponent(token),
|
||||
)
|
||||
const ic = info?.code?.code ?? info?.code
|
||||
const list = Array.isArray(info?.bo) ? info.bo
|
||||
: Array.isArray(info?.bo?.rows) ? info.bo.rows
|
||||
: Array.isArray(info?.bo?.list) ? info.bo.list
|
||||
: []
|
||||
if ((ic !== '0000' && ic !== 0 && ic !== '0') || !list.length) {
|
||||
setQrStatus('\u7528\u6237\u4fe1\u606f\u67e5\u8be2\u5931\u8d25')
|
||||
console.warn('[uds-auth] user-info after QR failed', info)
|
||||
return
|
||||
}
|
||||
} catch (err) {
|
||||
setQrStatus('\u7528\u6237\u4fe1\u606f\u67e5\u8be2\u5931\u8d25: ' + (err.message || err))
|
||||
return
|
||||
}
|
||||
setQrStatus('\u767b\u5f55\u6210\u529f\uff01')
|
||||
await refreshUser()
|
||||
setOpen(false)
|
||||
|
|
|
|||
|
|
@ -385,14 +385,21 @@ async function handleUserInfo(req, res) {
|
|||
'Origin': _currentConfig.uacBaseUrl,
|
||||
'Referer': _currentConfig.uacBaseUrl + '/'
|
||||
}
|
||||
if (token) headers[INTERNAL.authValueHeader] = token
|
||||
if (!token) {
|
||||
res.writeHead(400, { 'Content-Type': 'application/json' })
|
||||
res.end(JSON.stringify({ error: 'Missing token' }))
|
||||
return
|
||||
}
|
||||
headers[INTERNAL.authValueHeader] = token
|
||||
|
||||
const result = await new Promise((resolve, reject) => {
|
||||
const proxyReq = https.request({
|
||||
hostname: targetUrl.hostname,
|
||||
path: targetUrl.pathname,
|
||||
port: targetUrl.port || 443,
|
||||
path: targetUrl.pathname + targetUrl.search,
|
||||
method: 'POST',
|
||||
headers
|
||||
headers,
|
||||
timeout: 8000,
|
||||
}, (proxyRes) => {
|
||||
let data = ''
|
||||
proxyRes.on('data', chunk => data += chunk)
|
||||
|
|
@ -739,9 +746,11 @@ async function initServices(ctx, config) {
|
|||
await _rolesStore.init()
|
||||
|
||||
_authMiddleware = createAuthMiddleware({
|
||||
userSearchUrl: config.userSearchUrl,
|
||||
udsAuth: {
|
||||
baseUrl: config.uacBaseUrl,
|
||||
systemCode: config.loginSystemCode,
|
||||
userSearchUrl: config.userSearchUrl,
|
||||
empNoHeader: INTERNAL.empNoHeader,
|
||||
authValueHeader: INTERNAL.authValueHeader,
|
||||
},
|
||||
|
|
|
|||
|
|
@ -34,7 +34,12 @@ export function createAuthMiddleware(config, sessionStore, rolesStore) {
|
|||
* empNo + token → 调用户搜索接口;返回解析后的 profile 或 null
|
||||
*/
|
||||
async function verifyEmpNoAndToken(empNo, token) {
|
||||
if (!userSearchUrl || !empNo || !token) return null
|
||||
if (!userSearchUrl || !empNo || !token) {
|
||||
console.warn('[uds-auth] verifyEmpNoAndToken skipped: missing', {
|
||||
hasUrl: !!userSearchUrl, hasEmpNo: !!empNo, hasToken: !!token,
|
||||
})
|
||||
return null
|
||||
}
|
||||
try {
|
||||
const targetUrl = new URL(userSearchUrl)
|
||||
const body = JSON.stringify({
|
||||
|
|
@ -55,7 +60,7 @@ export function createAuthMiddleware(config, sessionStore, rolesStore) {
|
|||
|
||||
const isHttps = targetUrl.protocol === 'https:'
|
||||
const mod = await import(isHttps ? 'node:https' : 'node:http')
|
||||
const result = await new Promise((resolve, reject) => {
|
||||
const { statusCode, result } = await new Promise((resolve, reject) => {
|
||||
const req = mod.request({
|
||||
hostname: targetUrl.hostname,
|
||||
port: targetUrl.port || (isHttps ? 443 : 80),
|
||||
|
|
@ -67,7 +72,9 @@ export function createAuthMiddleware(config, sessionStore, rolesStore) {
|
|||
let data = ''
|
||||
res.on('data', (c) => { data += c })
|
||||
res.on('end', () => {
|
||||
try { resolve(JSON.parse(data)) } catch { resolve(null) }
|
||||
let parsed = null
|
||||
try { parsed = JSON.parse(data) } catch { parsed = { raw: String(data).slice(0, 300) } }
|
||||
resolve({ statusCode: res.statusCode, result: parsed })
|
||||
})
|
||||
})
|
||||
req.on('error', reject)
|
||||
|
|
@ -76,12 +83,21 @@ export function createAuthMiddleware(config, sessionStore, rolesStore) {
|
|||
req.end()
|
||||
})
|
||||
|
||||
const code = result?.code?.code || result?.code
|
||||
if (code !== '0000' && code !== 0 && code !== '0') return null
|
||||
const code = result?.code?.code ?? result?.code
|
||||
if (code !== '0000' && code !== 0 && code !== '0') {
|
||||
console.warn('[uds-auth] userSearch failed:', {
|
||||
empNo, statusCode, code, msg: result?.code?.msg || result?.msg || result?.raw,
|
||||
})
|
||||
return null
|
||||
}
|
||||
const list = Array.isArray(result?.bo) ? result.bo
|
||||
: Array.isArray(result?.bo?.rows) ? result.bo.rows
|
||||
: []
|
||||
if (!list.length) return null
|
||||
: Array.isArray(result?.bo?.list) ? result.bo.list
|
||||
: []
|
||||
if (!list.length) {
|
||||
console.warn('[uds-auth] userSearch empty bo:', { empNo, statusCode, keys: result && Object.keys(result) })
|
||||
return null
|
||||
}
|
||||
const emp = list[0]
|
||||
const resolvedEmpNo = String(
|
||||
emp.employeeShortId || emp.employeeNO || emp.empUIID || emp.empNo || empNo,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue