美文网首页
大意了,小程序接口调用不做token校验

大意了,小程序接口调用不做token校验

作者: _小肥羊 | 来源:发表于2020-12-27 22:37 被阅读0次

大意了,接口调用不做token校验

1

今天忙里偷闲,学习业内比较优秀的答题小程序,发现一个有意思的问题,该小程序在list接口竟然没有做token的安全校验,

1

1

{"msg":"ok","data": [{"count":10,"temp":1,"title":"\u5143\u65e6\u4e16\u754c\u5404\u56fd\u4e60\u4fd7\u77e5\u8bc6\u7ade\u8d5b","qid":"5fe2b0d9e983991aff836cad","joined":71,"del":0,"index_banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-23/c11995f3eed042519c5878471e9e734b.jpg","is_violation":0,"banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-23/c11995f3eed042519c5878471e9e734b.jpg","index_status":0}, {"count":10,"temp":1,"title":"\u5723\u8bde\u77e5\u8bc6\u95ee\u7b54","qid":"5fd32dee014de738117260d2","joined":289,"del":0,"index_banner":"https://cdn-xcxcustom.weiyoubot.cn/20201222/c2534c44f22bc1f699dd9b013634e5c3.jpg","is_violation":0,"banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-22/c618ea9cb9f54ffea167df9768ef3ac6.jpg","index_status":0}, {"count":5,"temp":1,"title":"\u70e7\u8111\u6311\u6218\uff0c\u4e0d\u52302%\u7684\u4eba\u80fd\u5168\u5bf9","qid":"5fd858eee9839920f9dea9ed","joined":270,"del":0,"index_banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-15/8e1bc491db974aabbca57f65f48f92b8.jpg","is_violation":0,"banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-15/8e1bc491db974aabbca57f65f48f92b8.jpg","index_status":0}, {"count":10,"temp":1,"title":"2020\u5e74\u5ea6\u6d41\u884c\u8bed\u6d4b\u8bd5\uff0c\u7b54\u5bf9\u516b\u989800\u540e\u90fd\u76f4\u547c\u5185\u884c","qid":"5fcf1c19e17b4a064095b8a5","joined":1000,"del":0,"index_banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-08/c6f1f3da143c4798a57c242004aa7619.jpg","is_violation":0,"banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-08/c6f1f3da143c4798a57c242004aa7619.jpg","index_status":0}, {"count":5,"temp":0,"title":"\u5c11\u6797\u5bfa\u77e5\u591a\u5c11\uff1f\u54ea\u4ef6\u5175\u5668\u662f\u5c11\u6797\u5bfa\u4e4b\u9996\uff1f","qid":"5fd85852014de75890a99f27","joined":42,"del":0,"index_banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-15/9324e207699a40fcb86cc3bfe8582283.jpg","is_violation":0,"banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-15/9324e207699a40fcb86cc3bfe8582283.jpg","index_status":0}, {"count":50,"temp":1,"title":"\u5065\u5eb7\u77e5\u8bc6100\u95ee\uff08\u4e0a\uff09\uff0c\u542b\u77e5\u8bc6\u70b9\u8bb2\u89e3","qid":"5fd85945014de758938708fa","joined":37,"del":0,"index_banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-15/714ca52b60ed4eeb9f588393a54bf90d.jpg","is_violation":0,"banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-15/714ca52b60ed4eeb9f588393a54bf90d.jpg","index_status":0}, {"count":50,"temp":1,"title":"\u5065\u5eb7\u77e5\u8bc6100\u95ee\uff08\u4e0b\uff09\uff0c\u542b\u77e5\u8bc6\u70b9\u8bb2\u89e3","qid":"5fd859c6e17b4a203f113992","joined":24,"del":0,"index_banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-15/399e864e47074ee188c192682e5a862d.jpg","is_violation":0,"banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-15/399e864e47074ee188c192682e5a862d.jpg","index_status":0}, {"count":10,"temp":1,"title":"\u571f\u5473\u60c5\u8bdd\u6d4b\u8bd5\uff0c90\u5206\u4ee5\u4e0a\u7684\uff0c\u4f60\u79bb\u8131\u5355\u4e0d\u8fdc\u4e86\u3002","qid":"5fc08108e17b4a600728b594","joined":500,"del":0,"index_banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-11-27/47e7f3560a9f42abb88f668700e81607.jpg","is_violation":0,"banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-11-27/47e7f3560a9f42abb88f668700e81607.jpg","index_status":0}, {"count":5,"temp":2,"title":"\u827a\u672f\u5e38\u8bc6\u6d4b\u8bd5","qid":"5fcf34c0c932846e5227546b","joined":201,"del":0,"index_banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-08/69c3962004eb472eb5073e99a92f84aa.jpg","is_violation":0,"banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-12-08/69c3962004eb472eb5073e99a92f84aa.jpg","index_status":0}, {"count":10,"temp":0,"title":"\u5564\u9152\u51b7\u77e5\u8bc6\uff0c\u7f8e\u56fd\u603b\u7edf\u662f\u8c03\u9152\u5e08\uff1f","qid":"5fc07cd2e17b4a60099d9d55","joined":56,"del":0,"index_banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-11-27/5033a84242b242b89b618c7a1b9c44a5.jpg","is_violation":0,"banner":"https://cdn-xcx-qunsou.weiyoubot.cn/xcx/2020-11-27/5033a84242b242b89b618c7a1b9c44a5.jpg","index_status":0}],"sta":0}

1

1

1

相关文章

  • 大意了,小程序接口调用不做token校验

    大意了,接口调用不做token校验 1 今天忙里偷闲,学习业内比较优秀的答题小程序,发现一个有意思的问题,该小程序...

  • 学术研究小程序接口 必须参数(token,time) 1.用户登录接口 post localhost/api/pu...

  • token验证的方法

    统一token处理 排除token校验注解类为不需要校验 token 的方法定义注解@Documented //标...

  • 微信小程序wx.navigateBack时,刷新上一个页面

    场景:我的小程序的登录是在所有请求时校验token, 若该请求需要token而没有token, 就会触发跳转到登录...

  • Token策略

    用户携带账号密码访问后端校验,校验成功后生成Token,并且给Token设置有效期,并且把Token放入至Redi...

  • 9.从零搭建WebApi接口开发框架-根据token控制接口请求

    生成中接口的请求必须加token进行权限校验,比如校验是否登录获取的token,校验该用户是否具体该接口访问权限等...

  • Token校验

    Token,就是令牌,最大的特点就是随机性,不可预测。一般黑客或软件无法猜测出来。 那么,Token有什么作用?又...

  • token校验

    摘自:https://mp.weixin.qq.com/s/yPdSQkSgIftWt6qH82Z4Rw[http...

  • 前后端分离项目——登录Token校验思路

    前言 根据token校验当前用户登录状态是Web项目的常见手段,我给自己的项目做token校验功能时,发现网上很多...

  • 自定义注解开发2

    需求 前端向后台发起请求时,希望某些请求需要校验token,某些请求不需要校验token,而只要在方法上加上注解的...

网友评论

      本文标题:大意了,小程序接口调用不做token校验

      本文链接:https://www.haomeiwen.com/subject/sbmanktx.html