Adding the new rewrite
This commit is contained in:
1 parent
4aca9f08d1
commit
9b48b01d1d
62 files changed
+4510
-1406
No files matched your search
@@ -0,0 +1,33 @@
|
||||
// Shared client-side helpers: CSRF, logout, fetch wrapper
|
||||
(function () {
|
||||
function getCsrfToken() {
|
||||
const meta = document.querySelector('meta[name="csrf-token"]');
|
||||
if (meta && meta.content) return meta.content;
|
||||
const m = document.cookie.match(/(?:^|;)\s*csrf_token=([^;]+)/);
|
||||
return m ? decodeURIComponent(m[1]) : '';
|
||||
}
|
||||
|
||||
window.apiFetch = async function (url, opts = {}) {
|
||||
const method = (opts.method || 'GET').toUpperCase();
|
||||
const headers = Object.assign({ Accept: 'application/json' }, opts.headers || {});
|
||||
if (method !== 'GET' && method !== 'HEAD') {
|
||||
headers['X-CSRF-Token'] = getCsrfToken();
|
||||
if (opts.body && !(opts.body instanceof FormData) && !headers['Content-Type']) {
|
||||
headers['Content-Type'] = 'application/json';
|
||||
}
|
||||
}
|
||||
const resp = await fetch(url, Object.assign({ credentials: 'same-origin' }, opts, { headers }));
|
||||
if (resp.status === 401) {
|
||||
window.location.href = '/login';
|
||||
throw new Error('unauthorized');
|
||||
}
|
||||
return resp;
|
||||
};
|
||||
|
||||
document.addEventListener('click', async (e) => {
|
||||
if (e.target && e.target.id === 'logout-btn') {
|
||||
await window.apiFetch('/api/logout', { method: 'POST' });
|
||||
window.location.href = '/login';
|
||||
}
|
||||
});
|
||||
})();
|
||||
Reference in new issue
Block a user