Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

appId和appsecret是不是不应该写在js中 #1

Open
Kiriyoai opened this issue Oct 17, 2016 · 5 comments
Open

appId和appsecret是不是不应该写在js中 #1

Kiriyoai opened this issue Oct 17, 2016 · 5 comments

Comments

@Kiriyoai
Copy link

把appId和appsecret都写在js上的话,是不是任何人也能拿到appId和appsecret并自己获取token对你的公众号做修改?

@jiangxianli
Copy link
Owner

jiangxianli commented Oct 17, 2016

@Kiriyoai 不是的,微信有安全域名验证的,只有在当前appID微信公众号指定的JS安全域名下使用该appId,appSecret才是有效的,
但是一般不建议暴露出appSecret。

@Kiriyoai
Copy link
Author

@jiangxianli 我用的是公众号测试账号,即使绑定了域名(我随便绑的百度域名),还是能调用创建菜单,删除菜单等api啊

@jiangxianli
Copy link
Owner

@Kiriyoai 微信菜单操作不属于微信JS-SDK操作范围,所以还是不要暴露你的appSecret。

@Kiriyoai
Copy link
Author

@jiangxianli 刚刚看到微信公众平台的文档说:"出于安全考虑,开发者必须在服务器端实现签名的逻辑"

@jiangxianli
Copy link
Owner

@Kiriyoai 是的。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants