Files
Oxicloud/static/js/core/csrf.js
T
Edouard Vanbelle 6f4abfcec4 refactor(js): avoid use of window.XXX and move to import/export
- change worker: do not cache html pages (not necessary)
- remove use of window.XXX and maximize import/export,
  this will provide more clarety,
  show circular dependencies + you will benefit IDE help
2026-04-14 19:05:01 +02:00

27 lines
851 B
JavaScript

/**
* CSRF double-submit cookie utility.
*
* Reads the `oxicloud_csrf` cookie (which is NOT HttpOnly) and provides
* its value as the `X-CSRF-Token` header on mutating requests.
*
* Usage:
* // In any fetch call that changes state:
* fetch(url, { method: 'POST', headers: { ...getCsrfHeaders(), 'Content-Type': 'application/json' } })
*
* The server-side `csrf_middleware` validates that the header value matches
* the cookie for every POST/PUT/DELETE/PATCH request authenticated via
* HttpOnly cookies.
*/
function getCsrfToken() {
const match = document.cookie.split('; ').find((row) => row.startsWith('oxicloud_csrf='));
return match ? match.split('=')[1] : '';
}
function getCsrfHeaders() {
const token = getCsrfToken();
return token ? { 'X-CSRF-Token': token } : {};
}
export { getCsrfHeaders, getCsrfToken };