<!doctype html>
<html lang="en">
<head>
    <meta charset="UTF-8">
    <title>Ajax Post 上传</title>
    <style>
        h1, h2 {
            font-weight: normal;
        }

        #msg {
            margin-top: 10px;
        }
    </style>
</head>
<body>

<h1>PostObject 上传(Policy 保护,Ajax POST 请求)</h1>

<input id="fileSelector" type="file">
<input id="submitBtn" type="submit">

<div id="msg"></div>

<script src="common/cos-auth.min.js"></script>
<script>
    (function () {

        // 请求用到的参数
        var Bucket = 'test-1250000000';
        var Region = 'ap-guangzhou';
        var protocol = location.protocol === 'https:' ? 'https:' : 'http:';
        var prefix = protocol + '//' + Bucket + '.cos.' + Region + '.myqcloud.com/';

        // 对更多字符编码的 url encode 格式
        var camSafeUrlEncode = function (str) {
            return encodeURIComponent(str)
                .replace(/!/g, '%21')
                .replace(/'/g, '%27')
                .replace(/\(/g, '%28')
                .replace(/\)/g, '%29')
                .replace(/\*/g, '%2A');
        };

        // 获取权限策略
        var getPostPolicyCredentials = function (opt, callback) {
            var url = 'http://127.0.0.1:3000/post-policy?key=' + encodeURIComponent(opt.Key);
            var xhr = new XMLHttpRequest();
            xhr.open('GET', url, true);
            xhr.onreadystatechange = function (e) {
                if (xhr.readyState === 4) {
                    if (xhr.status === 200) {
                        var credentials;
                        try {
                            credentials = (new Function('return ' + xhr.responseText))();
                        } catch (e) {}
                        if (credentials) {
                            callback(null, credentials);
                        } else {
                            console.error(xhr.responseText);
                            callback('获取签名出错');
                        }
                    } else {
                        callback('获取签名出错');
                    }
                }
            };
            xhr.send();
        };

        // 上传文件
        var uploadFile = function (file, callback) {
            var Key = 'dir/' + file.name; // 这里指定上传目录和文件名
            getPostPolicyCredentials({
                Bucket: Bucket,
                Key: Key,
                ACL: 'default'
            }, function (err, credentials) {
                var fd = new FormData();

                // 在当前目录下放一个空的 empty.html 以便让接口上传完成跳转回来
                fd.append('key', Key);

                // // 使用普通签名格式
                // fd.append('Signature', credentials.Authorization);
                // fd.append('x-cos-security-token', credentials.SecurityToken || '');

                // 使用 policy 签名保护格式
                credentials.securityToken && fd.append('x-cos-security-token', credentials.securityToken);
                fd.append('q-sign-algorithm', credentials.qSignAlgorithm);
                fd.append('q-ak', credentials.qAk);
                fd.append('q-key-time', credentials.qKeyTime);
                fd.append('q-signature', credentials.qSignature);
                fd.append('policy', credentials.policy);

                // 文件内容,file 字段放在表单最后,避免文件内容过长影响签名判断和鉴权
                fd.append('file', file);

                // xhr
                var url = prefix;
                var xhr = new XMLHttpRequest();
                xhr.open('POST', url, true);
                xhr.upload.onprogress = function (e) {
                    console.log('上传进度 ' + (Math.round(e.loaded / e.total * 10000) / 100) + '%');
                };
                xhr.onload = function () {
                    if (Math.floor(xhr.status / 100) === 2) {
                        var ETag = xhr.getResponseHeader('etag');
                        callback(null, {url: prefix + camSafeUrlEncode(Key).replace(/%2F/g, '/'), ETag: ETag});
                    } else {
                        callback('文件 ' + Key + ' 上传失败,状态码:' + xhr.status);
                    }
                };
                xhr.onerror = function () {
                    callback('文件 ' + Key + ' 上传失败,请检查是否没配置 CORS 跨域规则');
                };
                xhr.send(fd);
            });
        };

        // 监听表单提交
        document.getElementById('submitBtn').onclick = function (e) {
            var file = document.getElementById('fileSelector').files[0];
            if (!file) {
                document.getElementById('msg').innerText = '未选择上传文件';
                return;
            }
            file && uploadFile(file, function (err, data) {
                console.log(err || data);
                document.getElementById('msg').innerText = err ? err : ('上传成功,ETag=' + data.ETag);
            });
        };
    })();
</script>

</body>
</html>