Authored by ccbikai

获取到 UID 后删除cookie中的UID,防止有人从 cookie 读取

... ... @@ -8,6 +8,7 @@ module.exports = () => {
if (md5(key) === token) {
req.user.uid = uid;
delete req.cookies._YOHOUID;
}
next();
... ...