Files
EpicNext-Cms/src/lib/admin-fetch.ts
T
SimoandCursor 2de3696993
Local Build and Deploy / deploy (push) Successful in 1m38s
Enforce admin CSRF, harden catalog translate, use CMS hotel name for PayPal.
Mutating withAdmin routes now require a double-submit CSRF token; translate is capped at 500 items with audit logging; PayPal descriptions prefer siteSettings hotel_name.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:38:42 +02:00

32 lines
861 B
TypeScript

const MUTATING = new Set(["POST", "PUT", "PATCH", "DELETE"]);
/** Read the CSRF token injected by the admin layout `<meta name="csrf-token">`. */
export function getCsrfToken(): string | null {
if (typeof document === "undefined") return null;
return (
document
.querySelector('meta[name="csrf-token"]')
?.getAttribute("content") ?? null
);
}
/**
* Same-origin fetch for admin APIs. Attaches `x-csrf-token` on mutating methods.
*/
export function adminFetch(
input: RequestInfo | URL,
init?: RequestInit,
): Promise<Response> {
const method = (init?.method ?? "GET").toUpperCase();
const headers = new Headers(init?.headers);
if (MUTATING.has(method)) {
const token = getCsrfToken();
if (token) headers.set("x-csrf-token", token);
}
return fetch(input, {
...init,
headers,
credentials: init?.credentials ?? "same-origin",
});
}