微信扫码登录中转站。统一承接微信开放平台网站应用的授权回调,并把登录凭证安全分发回各业务前端。
/oauth/wechat/start/wechat/callback/api/public/oauth/wechat/exchange/healthza.com ─click──► b.com /oauth/wechat/start?client=a&return_path=/dashboard
│
│ state ⇒ KV {client, return_path, exp 5m}
▼
open.weixin.qq.com/connect/qrconnect (scope=snsapi_login)
│
▼
b.com /wechat/callback?code=…&state=…
│
│ code ⇒ openid/unionid/userinfo
│ ticket ⇒ KV {client, user, exp 2m, used:false}
▼
a.com /login/wechat-done?ticket=…&return_path=/dashboard
│
│ POST b.com/api/public/oauth/wechat/exchange
│ { ticket, client, client_secret }
▼
a.com BFF set-cookie session ──► 302 /dashboardb.com)。a.com / c.com / d.com 不需要在微信后台配置。CLIENTS_JSON 注册业务站点白名单。README.md。