Browse Source

csrf配置调整

MaiXinRong 4 years ago
parent
commit
463a5e06e5

+ 1 - 1
app/public/js/change_approval.js

@@ -123,7 +123,7 @@ const postDataWithAsync = function (url, data, successCallback, errorCallBack, s
         timeout: 60000,
         beforeSend: function(xhr) {
             let csrfToken = Cookies.get('csrfToken_j');
-            xhr.setRequestHeader('x-csrf-token_j', csrfToken);
+            xhr.setRequestHeader('x-csrf-token', csrfToken);
         },
         success: function(result){
             if (result.err === 0) {

+ 1 - 1
app/public/js/change_information_approval.js

@@ -383,7 +383,7 @@ const postDataWithAsync = function (url, data, successCallback, errorCallBack, s
         timeout: 60000,
         beforeSend: function(xhr) {
             let csrfToken = Cookies.get('csrfToken_j');
-            xhr.setRequestHeader('x-csrf-token_j', csrfToken);
+            xhr.setRequestHeader('x-csrf-token', csrfToken);
         },
         success: function(result){
             if (result.err === 0) {

+ 1 - 1
app/public/js/common_ajax.js

@@ -127,7 +127,7 @@ var CommonAjax = {
             async: isAsync,
             timeout: dftTimeOutMilSec,
             beforeSend: function (xhr) {
-                xhr.setRequestHeader('x-csrf-token_j', csrfToken);
+                xhr.setRequestHeader('x-csrf-token', csrfToken);
             },
             success: function(result){
                 if (result) {

+ 1 - 1
app/public/js/draw.js

@@ -220,7 +220,7 @@ Draw.prototype = {
     formData.append('image', blob, 'sign');
 
     xhr.open('POST', url, true);
-    xhr.setRequestHeader("x-csrf-token_j", csrf);
+    xhr.setRequestHeader("x-csrf-token", csrf);
     xhr.onload = () => {
       if ((xhr.status >= 200 && xhr.status < 300) || xhr.status === 304) {
         success(xhr.responseText);

+ 4 - 4
app/public/js/global.js

@@ -158,7 +158,7 @@ const postData = function (url, data, successCallback, errorCallBack, showWaitin
         timeout: 60000,
         beforeSend: function(xhr) {
             let csrfToken = Cookies.get('csrfToken_j');
-            xhr.setRequestHeader('x-csrf-token_j', csrfToken);
+            xhr.setRequestHeader('x-csrf-token', csrfToken);
         },
         success: function(result){
             if (result.err === 0) {
@@ -207,7 +207,7 @@ const postDataCompress = function (url, data, successCallback, errorCallBack, ht
         timeout: 80000, // 导入清单Excel(10w行)预计需要时间
         beforeSend: function(xhr) {
             let csrfToken = Cookies.get('csrfToken_j');
-            xhr.setRequestHeader('x-csrf-token_j', csrfToken);
+            xhr.setRequestHeader('x-csrf-token', csrfToken);
         },
         success: function(result){
             if (htype === 'progress') doneProgress();
@@ -267,7 +267,7 @@ const postDataWithFile = function (url, formData, successCallback, errorCallBack
         timeout: 60000,
         beforeSend: function(xhr) {
             let csrfToken = Cookies.get('csrfToken_j');
-            xhr.setRequestHeader('x-csrf-token_j', csrfToken);
+            xhr.setRequestHeader('x-csrf-token', csrfToken);
         },
         success: function(result){
             if (result.err === 0) {
@@ -311,7 +311,7 @@ const postDataWithFileProgress = function (url, formData, successCallback, error
         processData: false,
         beforeSend: function(xhr) {
             let csrfToken = Cookies.get('csrfToken_j');
-            xhr.setRequestHeader('x-csrf-token_j', csrfToken);
+            xhr.setRequestHeader('x-csrf-token', csrfToken);
         },
         success: function(result){
             doneProgress();

+ 1 - 1
app/public/js/login.js

@@ -94,7 +94,7 @@ $(document).ready(function() {
                 dataType: 'json',
                 beforeSend: function(xhr) {
                     let csrfToken = csrf;
-                    xhr.setRequestHeader('x-csrf-token_j', csrfToken);
+                    xhr.setRequestHeader('x-csrf-token', csrfToken);
                 },
                 success: function (result) {
                     if (result.err === 1) {

+ 1 - 1
app/public/js/setting.js

@@ -85,7 +85,7 @@ $(document).ready(() => {
                 },
                 beforeSend: function(xhr) {
                     let csrfToken = Cookies.get('csrfToken_j');
-                    xhr.setRequestHeader('x-csrf-token_j', csrfToken);
+                    xhr.setRequestHeader('x-csrf-token', csrfToken);
                     isChange = true;
                     btn.html('<i class="fa fa-spinner fa-pulse"></i>');
                 },

+ 1 - 1
app/public/js/wap/global.js

@@ -25,7 +25,7 @@ const postData = function (url, data, successCallback, errorCallBack, showWaitin
         timeout: 60000,
         beforeSend: function(xhr) {
             let csrfToken = Cookies.get('csrfToken_j');
-            xhr.setRequestHeader('x-csrf-token_j', csrfToken);
+            xhr.setRequestHeader('x-csrf-token', csrfToken);
         },
         success: function(result){
             if (result.err === 0) {

+ 1 - 1
app/view/wap/shenpi_change.ejs

@@ -367,7 +367,7 @@
             timeout: 60000,
             beforeSend: function(xhr) {
                 let csrfToken = Cookies.get('csrfToken_j');
-                xhr.setRequestHeader('x-csrf-token_j', csrfToken);
+                xhr.setRequestHeader('x-csrf-token', csrfToken);
             },
             success: function(result){
                 if (result.err === 0) {

+ 0 - 1
config/config.default.js

@@ -88,7 +88,6 @@ module.exports = appInfo => {
             ignoreJSON: false, // 默认为 false,当设置为 true 时,将会放过所有 content-type 为 `application/json` 的请求
             cookieName: 'csrfToken_j',    // csrf token's cookie name
             sessionName: 'csrfToken_j',   // csrf token's session name
-            headerName: 'x-csrf-token_j', // request csrf token's name in header
             bodyName: '_csrf_j',          // request csrf token's name in body
             queryName: '_csrf_j',         // request csrf token's name in query
         },

+ 1 - 2
config/web.js

@@ -40,14 +40,13 @@ const JsFiles = {
         '/public/js/messages_zh.js',
         '/public/js/popper/popper.min.js',
         '/public/js/bootstrap/bootstrap.min.js',
-        '/public/js/vue/vue.js',
+        '/public/js/vue/vue.min.js',
         '/public/js/component/input.js',
         '/public/js/cookies.js',
         '/public/js/jquery-contextmenu/jquery.ui.position.min.js',
         '/public/js/jquery-contextmenu/jquery.contextMenu.min.js',
         '/public/js/lodash.js',
         '/public/js/lz-string/lz-string.js',
-        '/public/js/number-precision.js',
         '/public/js/toastr.min.js',
         '/public/js/global.js',
     ],