Local Build and Deploy / deploy (push) Successful in 1m38s
Mutating withAdmin routes now require a double-submit CSRF token; translate is capped at 500 items with audit logging; PayPal descriptions prefer siteSettings hotel_name. Co-authored-by: Cursor <[email protected]>
32 lines
861 B
TypeScript
32 lines
861 B
TypeScript
const MUTATING = new Set(["POST", "PUT", "PATCH", "DELETE"]);
|
|
|
|
/** Read the CSRF token injected by the admin layout `<meta name="csrf-token">`. */
|
|
export function getCsrfToken(): string | null {
|
|
if (typeof document === "undefined") return null;
|
|
return (
|
|
document
|
|
.querySelector('meta[name="csrf-token"]')
|
|
?.getAttribute("content") ?? null
|
|
);
|
|
}
|
|
|
|
/**
|
|
* Same-origin fetch for admin APIs. Attaches `x-csrf-token` on mutating methods.
|
|
*/
|
|
export function adminFetch(
|
|
input: RequestInfo | URL,
|
|
init?: RequestInit,
|
|
): Promise<Response> {
|
|
const method = (init?.method ?? "GET").toUpperCase();
|
|
const headers = new Headers(init?.headers);
|
|
if (MUTATING.has(method)) {
|
|
const token = getCsrfToken();
|
|
if (token) headers.set("x-csrf-token", token);
|
|
}
|
|
return fetch(input, {
|
|
...init,
|
|
headers,
|
|
credentials: init?.credentials ?? "same-origin",
|
|
});
|
|
}
|