Files
device-voice-h5/openspec/changes/update-july-h5-c-iteration/specs/c-login-access/spec.md
luo 4f281da778
All checks were successful
构建并部署前端到生产环境 / build-and-deploy (push) Successful in 1m11s
feat: 7月迭代
2026-07-27 18:13:19 +08:00

24 lines
1.3 KiB
Markdown

## ADDED Requirements
### Requirement: C-end login SHALL honor asset verification access decisions
The H5/C client SHALL call `POST /api/c/v1/auth/verify-asset` before continuing the asset login flow. A business failure or C-end login restriction returned by the endpoint SHALL be shown using the backend business message, and the client SHALL NOT continue to obtain, persist, or use an asset token for that login attempt.
#### Scenario: Asset verification allows login
- **WHEN** asset verification succeeds and returns an asset token
- **THEN** the client SHALL persist the identifier and returned asset token and continue the existing login flow
#### Scenario: Shop forbids a new C-end login
- **WHEN** asset verification returns a business failure indicating that the shop has forbidden C-end login
- **THEN** the client SHALL display the backend error message
- **AND** the client SHALL stop the current login flow before WeChat authorization or token persistence
- **AND** the client SHALL not revoke an already-issued token as a side effect
#### Scenario: Asset verification fails without a usable token
- **WHEN** the verification request returns an error response or no usable asset token
- **THEN** the client SHALL display the existing request/business error
- **AND** the client SHALL leave the current login attempt unauthenticated