policy-form.html 5.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144
  1. <!doctype html>
  2. <html lang="en">
  3. <head>
  4. <meta charset="UTF-8">
  5. <title>Form 表单简单上传</title>
  6. <style>h1, h2 {font-weight: normal;}#msg {margin-top:10px;}</style>
  7. </head>
  8. <body>
  9. <h1>PostObject 上传(Policy 保护,Form 表单上传)</h1>
  10. <div>最低兼容到 IE6 上传,使用 policy 签名保护,不支持 onprogress</div>
  11. <form id="form" target="submitTarget" action="" method="post" enctype="multipart/form-data" accept="*/*">
  12. <input id="fileSelector" name="file" type="file">
  13. <input id="submitBtn" type="button" value="提交">
  14. </form>
  15. <iframe id="submitTarget" name="submitTarget" style="display:none;" frameborder="0"></iframe>
  16. <div id="msg"></div>
  17. <script src="common/cos-auth.min.js"></script>
  18. <script>
  19. (function () {
  20. // 请求用到的参数
  21. var Bucket = 'test-1250000000';
  22. var Region = 'ap-guangzhou';
  23. var protocol = location.protocol === 'https:' ? 'https:' : 'http:';
  24. var prefix = protocol + '//' + Bucket + '.cos.' + Region + '.myqcloud.com/';
  25. var fileSelector = document.getElementById('fileSelector');
  26. var form = document.getElementById('form');
  27. form.action = prefix;
  28. // 对更多字符编码的 url encode 格式
  29. var camSafeUrlEncode = function (str) {
  30. return encodeURIComponent(str)
  31. .replace(/!/g, '%21')
  32. .replace(/'/g, '%27')
  33. .replace(/\(/g, '%28')
  34. .replace(/\)/g, '%29')
  35. .replace(/\*/g, '%2A');
  36. };
  37. // 获取权限策略
  38. var getPostPolicyCredentials = function (opt, callback) {
  39. var url = 'http://127.0.0.1:3000/post-policy?key=' + encodeURIComponent(opt.Key);
  40. var xhr = new XMLHttpRequest();
  41. xhr.open('GET', url, true);
  42. xhr.onreadystatechange = function (e) {
  43. if (xhr.readyState === 4) {
  44. if (xhr.status === 200) {
  45. var credentials;
  46. try {
  47. credentials = (new Function('return ' + xhr.responseText))();
  48. } catch (e) {}
  49. if (credentials) {
  50. callback(null, credentials);
  51. } else {
  52. console.error(xhr.responseText);
  53. callback('获取签名出错');
  54. }
  55. } else {
  56. callback('获取签名出错');
  57. }
  58. }
  59. };
  60. xhr.send();
  61. };
  62. // 监听上传完成
  63. var Key;
  64. var submitTarget = document.getElementById('submitTarget');
  65. var showMessage = function (err, data) {
  66. console.log(err || data);
  67. document.getElementById('msg').innerText = err ? err : ('上传成功,ETag=' + data.ETag);
  68. };
  69. submitTarget.onload = function () {
  70. var search;
  71. try {
  72. search = submitTarget.contentWindow.location.search.substr(1);
  73. } catch (e) {
  74. showMessage('文件 ' + Key + ' 上传失败');
  75. }
  76. if (search) {
  77. var items = search.split('&');
  78. var i, arr, data = {};
  79. for (i = 0; i < items.length; i++) {
  80. arr = items[i].split('=');
  81. data[arr[0]] = decodeURIComponent(arr[1] || '');
  82. }
  83. showMessage(null, {url: prefix + camSafeUrlEncode(Key).replace(/%2F/g, '/'), ETag: data.etag});
  84. } else {
  85. }
  86. };
  87. var setFormField = function (key, value) {
  88. var el = document.getElementById(key);
  89. if (!el) {
  90. el = document.createElement('input');
  91. el.hidden = true;
  92. el.id = key;
  93. el.name = key;
  94. form.insertBefore(el, fileSelector);
  95. }
  96. el.setAttribute('value', value); // 需要保证 file 在表单最后
  97. el.value = value;
  98. };
  99. // 发起上传
  100. document.getElementById('submitBtn').onclick = function (e) {
  101. var filePath = document.getElementById('fileSelector').value;
  102. if (!filePath) {
  103. document.getElementById('msg').innerText = '未选择上传文件';
  104. return;
  105. }
  106. Key = 'dir/' + filePath.match(/[\\\/]?([^\\\/]+)$/)[1]; // 这里指定上传目录和文件名
  107. // 获取签名保护字段
  108. getPostPolicyCredentials({
  109. Key: Key,
  110. }, function (err, credentials) {
  111. // 在当前目录下放一个空的 empty.html 以便让接口上传完成跳转回来
  112. setFormField('success_action_redirect', location.href.substr(0, location.href.lastIndexOf('/') + 1) + 'empty.html');
  113. setFormField('key', Key);
  114. // 使用 policy 签名保护格式
  115. credentials.securityToken && setFormField('x-cos-security-token', credentials.securityToken);
  116. setFormField('q-sign-algorithm', credentials.qSignAlgorithm);
  117. setFormField('q-ak', credentials.qAk);
  118. setFormField('q-key-time', credentials.qKeyTime);
  119. setFormField('q-signature', credentials.qSignature);
  120. setFormField('policy', credentials.policy);
  121. // 提交表单
  122. form.submit();
  123. });
  124. };
  125. })();
  126. </script>
  127. </body>
  128. </html>