【问题标题】:Simple form submission redirect to wrong page, why?简单的表单提交重定向到错误的页面,为什么?
【发布时间】:2018-12-23 03:32:42
【问题描述】:

我无法理解 Google App Script 中的这种行为,谁能解释一下?

这是一个绑定到工作表的非常简单的脚本。代码:

代码.js

function doGet() {
  return HtmlService.createHtmlOutputFromFile("index.html");
}

function doPost() {
  return HtmlService.createHtmlOutputFromFile("index.html");
}

index.html

<!DOCTYPE html>
<html>
  <head>
    <base target="_top">
  </head>
  <body>
    <form id="form" name="form" action="" method="POST">
      <input type="submit" id="submit" name="submit" value="submit">
    </form>
  </body>
</html>

看起来很简单吧?那么当你点击提交按钮时,页面重定向到一个空白页面。

我已经知道如何解决此问题(通过使用 script.run 甚至通过查询页面的 URL 来进行 hackier),但我想知道这里为什么会出错,因为 doPost 方法的意义何在如果你甚至不能使用它。

【问题讨论】:

    标签: google-apps-script web-applications forms http-post


    【解决方案1】:

    这是因为出于安全原因,您的页面是从另一个 URL *.googleusercontent.com 提供的。 doPost 方法的要点是,只要您知道已发布的 url,您就可以在任何服务器上的任何位置从您的客户端(例如本地 Python 脚本/nodeJs)发布到已发布的 url。

    【讨论】:

    • 您能描述一下这个安全原因吗?我真的不明白它是如何工作的。
    • @snaplizard 实际 url 是 script.google.com/* 这是域 google.com 从技术上讲,如果它在 Google.com 中运行,您的脚本将可以访问所有 Google cookie,甚至访问用户的身份验证 cookie您的网络应用程序。此外,您可以在网页中执行任何操作。为防止这种情况,Google 将您的网页放在来自 googleusercontent.com 的 iframe 中。因此,顶级框架/父级可以强制执行某些规则并清理您的代码 - 因为它在 iframe 中运行。它还可以注入任意代码(如google 和google.script.run)。我假设您已经知道如何解决这个问题。
    • 谢谢,但您能否更详细地解释一下,或者是否有某种关于此安全功能的文档?我可以解决这个问题,但不能以允许 POST 请求实际通过的方式。
    • that would allow a POST request to actually go through 您需要更改“action={url}”,其中 url 是实际发布的 url(script.google.com)。您还可以使用模板化的 html:"action=&lt;?=google.script.run.getUrl()?&gt;"stackoverflow.com/a/49925624 getUrl 是一个服务器端函数,用于检索发布的 url。或者,参见示例 form 一些文档:developers.google.com/apps-script/guides/html/restrictions developers.google.com/apps-script/guides/content#redirects
    猜你喜欢
    • 2020-09-04
    • 2018-10-31
    • 2012-11-25
    • 1970-01-01
    • 2020-02-13
    • 2018-09-12
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多