Repository navigation
refactor: 凭证接口改名 + 应用凭证返回完整凭证 - #4
Merged
Merged
Conversation
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
按官方 auth-token 文档统一凭证模型的术语和接口命名:应用凭证(CLIENT_CREDENTIALS,代表应用本身,用于开发调试/服务端联调/无需用户身份的后台任务)和用户授权凭证(AUTHORIZATION_CODE,绑定 openId,代表真实登录用户)。
getAccessToken()→getAppAccessToken(),且从返回裸 string 改为返回完整凭证{accessToken, expiresAt, refreshToken, openId}—— 应用凭证的响应本来就带 refreshToken 和过期时间,旧签名把它们丢了。TokenStore缓存条目同步扩字段,缓存命中与新换取返回同样完整的对象。code2Session()→getUserAccessToken()。旧名直接删除,不留废弃别名(尚无外部使用者)。me({accessToken})、Javame(QdmpContext.of(...))、GoWithAccessToken(...)),续期用auth.refreshToken()自己调,SDK 不缓存用户凭证、不代管、不做任何自动重试——401 原样抛给调用方。调用方也可以完全不用getUserAccessToken,自己实现拿凭证那一步。qd.login()(对应原生接口 signingenerate-code),删掉wx.login()这个微信类比;README 去掉平台文档内容和db.xxx假设。实测更正了两处与文档字面不符的地方:真实响应字段是驼峰且
expiresAt为字符串(文档写的 snake_case + 数字型expires_at照做会调不通);错误码 10003 的实际 message 是「授权码错误或超过 5 分钟」,授权码有 5 分钟有效期。三端门禁全绿(Node 91 / Java 119 / Go 83 测试,含 lint、staticcheck、checkstyle、spotless),三端均已对真实线上服务跑通 e2e:应用凭证完整四字段、缓存命中路径字段一致、自己调 refreshToken 续期、ctx 必传形态调通、坏 token 原样抛出无自动重试——三端结果一致。
🤖 Generated with Claude Code