Files
device-voice-h5/openspec/changes/update-july-h5-c-iteration/specs/c-login-access/spec.md
luo 4f281da778
All checks were successful
构建并部署前端到生产环境 / build-and-deploy (push) Successful in 1m11s
feat: 7月迭代
2026-07-27 18:13:19 +08:00

1.3 KiB

ADDED Requirements

Requirement: C-end login SHALL honor asset verification access decisions

The H5/C client SHALL call POST /api/c/v1/auth/verify-asset before continuing the asset login flow. A business failure or C-end login restriction returned by the endpoint SHALL be shown using the backend business message, and the client SHALL NOT continue to obtain, persist, or use an asset token for that login attempt.

Scenario: Asset verification allows login

  • WHEN asset verification succeeds and returns an asset token
  • THEN the client SHALL persist the identifier and returned asset token and continue the existing login flow

Scenario: Shop forbids a new C-end login

  • WHEN asset verification returns a business failure indicating that the shop has forbidden C-end login
  • THEN the client SHALL display the backend error message
  • AND the client SHALL stop the current login flow before WeChat authorization or token persistence
  • AND the client SHALL not revoke an already-issued token as a side effect

Scenario: Asset verification fails without a usable token

  • WHEN the verification request returns an error response or no usable asset token
  • THEN the client SHALL display the existing request/business error
  • AND the client SHALL leave the current login attempt unauthenticated