chore: 去掉未上线前的旧兼容垫片,板块流收口到首页
鉴权只认 cookie、SEO 只走 Next、sort 与推荐对齐;删除 Bearer、Go sitemap、post_type 回填等冗余路径。 Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -57,34 +57,23 @@ func setAuthCookies(c *gin.Context, accessToken, refreshToken string, secure boo
|
||||
})
|
||||
}
|
||||
|
||||
// clearAuthCookies 清除所有认证 cookie。
|
||||
// 除当前名称外,还需兼容清除:
|
||||
// - 启用 __Host- 前缀之前的旧无前缀名称(Path=/)
|
||||
// - 更早期 Path=/api/auth 的旧 refresh cookie
|
||||
// clearAuthCookies 清除当前契约下的三枚认证 cookie(名称随 ConfigureCookieNames,Path=/)。
|
||||
func clearAuthCookies(c *gin.Context, secure bool) {
|
||||
cookies := []struct{ name, path string }{
|
||||
{service.CookieName, "/"},
|
||||
{service.RefreshCookieName, "/"},
|
||||
{service.CSRFCookieName, "/"},
|
||||
cookies := []struct {
|
||||
name string
|
||||
httpOnly bool
|
||||
}{
|
||||
{service.CookieName, true},
|
||||
{service.RefreshCookieName, true},
|
||||
{service.CSRFCookieName, false},
|
||||
}
|
||||
// 当前生产名称带 __Host- 前缀时,旧无前缀 cookie 仍残留在浏览器中
|
||||
if service.CookieName != "j13_token" {
|
||||
cookies = append(cookies,
|
||||
struct{ name, path string }{"j13_token", "/"},
|
||||
struct{ name, path string }{"j13_refresh", "/"},
|
||||
struct{ name, path string }{"j13_csrf", "/"},
|
||||
)
|
||||
}
|
||||
// 更早期的 refresh cookie 只挂在 /api/auth 下
|
||||
cookies = append(cookies, struct{ name, path string }{"j13_refresh", "/api/auth"})
|
||||
|
||||
for _, ck := range cookies {
|
||||
http.SetCookie(c.Writer, &http.Cookie{
|
||||
Name: ck.name,
|
||||
Value: "",
|
||||
Path: ck.path,
|
||||
Path: "/",
|
||||
MaxAge: -1,
|
||||
HttpOnly: true,
|
||||
HttpOnly: ck.httpOnly,
|
||||
Secure: secure,
|
||||
SameSite: http.SameSiteLaxMode,
|
||||
Expires: time.Unix(0, 0),
|
||||
|
||||
Reference in New Issue
Block a user