<!doctype html> <html lang="en"> <head> <meta charset="UTF-8"> <title>Ajax Post 上传</title> <style> h1, h2 { font-weight: normal; } #msg { margin-top: 10px; } </style> </head> <body> <h1>PostObject 上传(Policy 保护,Ajax POST 请求)</h1> <input id="fileSelector" type="file"> <input id="submitBtn" type="submit"> <div id="msg"></div> <script src="common/cos-auth.min.js"></script> <script> (function () { // 请求用到的参数 var Bucket = 'test-1250000000'; var Region = 'ap-guangzhou'; var protocol = location.protocol === 'https:' ? 'https:' : 'http:'; var prefix = protocol + '//' + Bucket + '.cos.' + Region + '.myqcloud.com/'; // 对更多字符编码的 url encode 格式 var camSafeUrlEncode = function (str) { return encodeURIComponent(str) .replace(/!/g, '%21') .replace(/'/g, '%27') .replace(/\(/g, '%28') .replace(/\)/g, '%29') .replace(/\*/g, '%2A'); }; // 获取权限策略 var getPostPolicyCredentials = function (opt, callback) { var url = 'http://127.0.0.1:3000/post-policy?key=' + encodeURIComponent(opt.Key); var xhr = new XMLHttpRequest(); xhr.open('GET', url, true); xhr.onreadystatechange = function (e) { if (xhr.readyState === 4) { if (xhr.status === 200) { var credentials; try { credentials = (new Function('return ' + xhr.responseText))(); } catch (e) {} if (credentials) { callback(null, credentials); } else { console.error(xhr.responseText); callback('获取签名出错'); } } else { callback('获取签名出错'); } } }; xhr.send(); }; // 上传文件 var uploadFile = function (file, callback) { var Key = 'dir/' + file.name; // 这里指定上传目录和文件名 getPostPolicyCredentials({ Bucket: Bucket, Key: Key, ACL: 'default' }, function (err, credentials) { var fd = new FormData(); // 在当前目录下放一个空的 empty.html 以便让接口上传完成跳转回来 fd.append('key', Key); // // 使用普通签名格式 // fd.append('Signature', credentials.Authorization); // fd.append('x-cos-security-token', credentials.SecurityToken || ''); // 使用 policy 签名保护格式 credentials.securityToken && fd.append('x-cos-security-token', credentials.securityToken); fd.append('q-sign-algorithm', credentials.qSignAlgorithm); fd.append('q-ak', credentials.qAk); fd.append('q-key-time', credentials.qKeyTime); fd.append('q-signature', credentials.qSignature); fd.append('policy', credentials.policy); // 文件内容,file 字段放在表单最后,避免文件内容过长影响签名判断和鉴权 fd.append('file', file); // xhr var url = prefix; var xhr = new XMLHttpRequest(); xhr.open('POST', url, true); xhr.upload.onprogress = function (e) { console.log('上传进度 ' + (Math.round(e.loaded / e.total * 10000) / 100) + '%'); }; xhr.onload = function () { if (Math.floor(xhr.status / 100) === 2) { var ETag = xhr.getResponseHeader('etag'); callback(null, {url: prefix + camSafeUrlEncode(Key).replace(/%2F/g, '/'), ETag: ETag}); } else { callback('文件 ' + Key + ' 上传失败,状态码:' + xhr.status); } }; xhr.onerror = function () { callback('文件 ' + Key + ' 上传失败,请检查是否没配置 CORS 跨域规则'); }; xhr.send(fd); }); }; // 监听表单提交 document.getElementById('submitBtn').onclick = function (e) { var file = document.getElementById('fileSelector').files[0]; if (!file) { document.getElementById('msg').innerText = '未选择上传文件'; return; } file && uploadFile(file, function (err, data) { console.log(err || data); document.getElementById('msg').innerText = err ? err : ('上传成功,ETag=' + data.ETag); }); }; })(); </script> </body> </html>