fix: 修复关注按钮 CSRF 403 + 缺少样式 + IncrCount SQL 错误

- 修复 CSRF 403:移除 space/index.html 中手动设置 X-CSRF-Token 头(与 common.js 自动注入冲突导致 token 重复)
- 修复按钮无样式:header.html 新增 ExtraCSS2 支持,space 页面加载 follow.css
- 修复 IncrCount SQL 错误:follow_repo.go 中 users 表列名修正 id → uid
This commit is contained in:
2026-06-01 20:16:51 +08:00
parent ae98d33edf
commit bab8e47d63
4 changed files with 6 additions and 5 deletions

View File

@ -17,5 +17,8 @@
{{if .ExtraCSS}}
<link rel="stylesheet" href="{{.ExtraCSS}}?v={{assetV .ExtraCSS}}">
{{end}}
{{if .ExtraCSS2}}
<link rel="stylesheet" href="{{.ExtraCSS2}}?v={{assetV .ExtraCSS2}}">
{{end}}
<script src="/shared/static/js/utils.js?v={{assetV "/shared/static/js/utils.js"}}"></script>
</head>

View File

@ -104,8 +104,6 @@
var followBtn = document.getElementById('followBtn');
if (!followBtn) return;
var targetUid = followBtn.getAttribute('data-uid');
var csrfMeta = document.querySelector('meta[name="csrf-token"]');
var csrfToken = csrfMeta ? csrfMeta.getAttribute('content') : '';
// 四个按钮状态文案
var labels = {
@ -149,7 +147,6 @@
followBtn.classList.add('waiting');
var xhr = new XMLHttpRequest();
xhr.open('POST', '/api/users/' + targetUid + '/follow', true);
xhr.setRequestHeader('X-CSRF-Token', csrfToken);
xhr.onreadystatechange = function() {
if (xhr.readyState === 4) {
followBtn.classList.remove('waiting');