1/* 2 * ADOBE CONFIDENTIAL 3 * 4 * Copyright 2015 Adobe Systems Incorporated 5 * All Rights Reserved. 6 * 7 * NOTICE: All information contained herein is, and remains 8 * the property of Adobe Systems Incorporated and its suppliers, 9 * if any. The intellectual and technical concepts contained 10 * herein are proprietary to Adobe Systems Incorporated and its 11 * suppliers and may be covered by U.S. and Foreign Patents, 12 * patents in process, and are protected by trade secret or copyright law. 13 * Dissemination of this information or reproduction of this material 14 * is strictly forbidden unless prior written permission is obtained 15 * from Adobe Systems Incorporated. 16 * 17 */ 18/* global CQURLInfo:false */ 19(function(window) { 20 "use strict"; 21 22 window.Granite = window.Granite || {}; 23 window.Granite.HTTP = window.Granite.HTTP || {}; 24 25 var contextPath = null; 26 27 function detectContextPath() { 28 // eslint-disable-next-line max-len 29 var SCRIPT_URL_REGEXP = /^(?:http|https):\/\/[^/]+(\/.*)\/(?:etc\.clientlibs|etc(\/.*)*\/clientlibs|libs(\/.*)*\/clientlibs|apps(\/.*)*\/clientlibs|etc\/designs).*\.js(\?.*)?$/; 30 try { 31 if (window.CQURLInfo) { 32 contextPath = CQURLInfo.contextPath || ""; 33 } else { 34 var scripts = document.getElementsByTagName("script"); 35 for (var i = 0; i < scripts.length; i++) { 36 var result = SCRIPT_URL_REGEXP.exec(scripts[i].src); 37 if (result) { 38 contextPath = result[1]; 39 return; 40 } 41 } 42 contextPath = ""; 43 } 44 } catch (e) { 45 // ignored 46 } 47 } 48 49 window.Granite.HTTP.externalize = window.Granite.HTTP.externalize || function(url) { 50 if (contextPath === null) { 51 detectContextPath(); 52 } 53 54 try { 55 if (url.indexOf("/") === 0 && contextPath && url.indexOf(contextPath + "/") !== 0) { 56 url = contextPath + url; 57 } 58 } catch (e) { 59 // ignored 60 } 61 62 return url; 63 }; 64})(this); 65 66/* 67 * ADOBE CONFIDENTIAL 68 * 69 * Copyright 2015 Adobe Systems Incorporated 70 * All Rights Reserved. 71 *
72 * NOTICE: All information contained herein is, and remains 73 * the property of Adobe Systems Incorporated and its suppliers, 74 * if any. The intellectual and technical concepts contained 75 * herein are proprietary to Adobe Systems Incorporated and its 76 * suppliers and may be covered by U.S. and Foreign Patents, 77 * patents in process, and are protected by trade secret or copyright law. 78 * Dissemination of this information or reproduction of this material 79 * is strictly forbidden unless prior written permission is obtained 80 * from Adobe Systems Incorporated. 81 * 82 */ 83(function(factory) { 84 "use strict"; 85 86 // GRANITE-22281 Check for multiple initialization 87 if (window.Granite.csrf) { 88 return; 89 } 90 91 window.Granite.csrf = factory(window.Granite.HTTP); 92}(function(http) { 93 "use strict"; 94 95 // AdobePatentID="P5296" 96 97 function Promise() { 98 this._handler = []; 99 } 100 101 Promise.prototype = { 102 then: function(resolveFn, rejectFn) { 103 this._handler.push({ resolve: resolveFn, reject: rejectFn }); 104 }, 105 resolve: function() { 106 this._execute("resolve", arguments); 107 }, 108 reject: function() { 109 this._execute("reject", arguments); 110 }, 111 _execute: function(result, args) { 112 if (this._handler === null) { 113 throw new Error("Promise already completed."); 114 } 115 116 for (var i = 0, ln = this._handler.length; i < ln; i++) { 117 this._handler[i][result].apply(window, args); 118 } 119 120 this.then = function(resolveFn, rejectFn) { 121 (result === "resolve" ? resolveFn : rejectFn).apply(window, args); 122 }; 123 124 this._handler = null; 125 } 126 }; 127 128 function verifySameOrigin(url) { 129 // url could be relative or scheme relative or absolute 130 // host + port 131 var host = document.location.host; 132 var protocol = document.location.protocol; 133 var relativeOrigin = "//" + host; 134 var origin = protocol + relativeOrigin; 135 136 // Allow absolute or scheme relative URLs to same origin 137 return (url === origin || url.slice(0, origin.length + 1) === origin + "/") || 138 (url === relativeOrigin || url.slice(0, relativeOrigin.length + 1) === relativeOrigin + "/") || 139 // or any other URL that isn't scheme relative or absolute i.e relative. 140 !(/^(\/\/|http:|https:).*/.test(url)); 141 } 142 143 var FIELD_NAME = ":cq_csrf_token"; 144 var HEADER_NAME = "CSRF-Token"; 145 var TOKEN_SERVLET = http.externalize("/libs/granite/csrf/token.json"); 146 147 var promise; 148 var globalToken; 149 150 function logFailRequest(error) { 151 if (window.console) { 152 // eslint-disable-next-line no-console 153 console.warn("CSRF data not available;" + 154 "The data may be unavailable by design, such as during non-authenticated requests: " + error); 155 } 156 } 157 158 function getToken() { 159 var localPromise = new Promise(); 160 promise = localPromise; 161 162 var xhr = new XMLHttpRequest(); 163 xhr.onreadystatechange = function() { 164 if (xhr.readyState === 4) { 165 try { 166 var data = JSON.parse(xhr.responseText); 167 globalToken = data.token; 168 localPromise.resolve(globalToken); 169 } catch (ex) { 170 logFailRequest(ex); 171 localPromise.reject(xhr.responseText); 172 } 173 } 174 }; 175 xhr.open("GET", TOKEN_SERVLET, true); 176 xhr.send(); 177 178 return localPromise; 179 } 180 181 function getTokenSync() { 182 var xhr = new XMLHttpRequest(); 183 xhr.open("GET", TOKEN_SERVLET, false); 184 xhr.send(); 185 186 try { 187 return globalToken = JSON.parse(xhr.responseText).token; 188 } catch (ex) { 189 logFailRequest(ex); 190 } 191 } 192 193 function clearToken() { 194 globalToken = undefined; 195 getToken(); 196 } 197 198 function addField(form) { 199 var action = form.getAttribute("action"); 200 if (form.method.toUpperCase() === "GET" || (action && !verifySameOrigin(action))) { 201 return; 202 } 203 204 if (!globalToken) { 205 getTokenSync(); 206 } 207 208 if (!globalToken) { 209 return; 210 } 211 212 var input = form.querySelector('input[name="' + FIELD_NAME + '"]'); 213 214 if (!input) { 215 input = document.createElement("input"); 216 input.setAttribute("type", "hidden"); 217 input.setAttribute("name", FIELD_NAME); 218 form.appendChild(input); 219 } 220 221 input.setAttribute("value", globalToken); 222 } 223 224 function handleForm(document) { 225 var handler = function(ev) { 226 var t = ev.target; 227 228 if (t.nodeName === "FORM") { 229 addField(t); 230 } 231 }; 232 233 if (document.addEventListener) { 234 document.addEventListener("submit", handler, true); 235 } else if (document.attachEvent) { 236 document.attachEvent("submit", handler); 237 } 238 } 239 240 handleForm(document); 241 242 var open = XMLHttpRequest.prototype.open; 243 244 XMLHttpRequest.prototype.open = function(method, url, async) { 245 if (method.toLowerCase() !== "get" && verifySameOrigin(url)) { 246 this._csrf = true; 247 this._async = async; 248 } 249 250 return open.apply(this, arguments); 251 }; 252 253 var send = XMLHttpRequest.prototype.send; 254 255 XMLHttpRequest.prototype.send = function() { 256 if (!this._csrf) { 257 send.apply(this, arguments); 258 return; 259 } 260 261 if (globalToken) { 262 this.setRequestHeader(HEADER_NAME, globalToken); 263 send.apply(this, arguments); 264 return; 265 } 266 267 if (this._async === false) { 268 getTokenSync(); 269 270 if (globalToken) { 271 this.setRequestHeader(HEADER_NAME, globalToken); 272 } 273 274 send.apply(this, arguments); 275 return; 276 } 277 278 var self = this; 279 var args = Array.prototype.slice.call(arguments); 280 281 promise.then(function(token) { 282 self.setRequestHeader(HEADER_NAME, token); 283 send.apply(self, args); 284 }, function() { 285 send.apply(self, args); 286 }); 287 }; 288 289 var submit = HTMLFormElement.prototype.submit; 290 291 HTMLFormElement.prototype.submit = function() { 292 addField(this); 293 return submit.apply(this, arguments); 294 }; 295 296 if (window.Node) { 297 var ac = Node.prototype.appendChild; 298 299 Node.prototype.appendChild = function() { 300 var result = ac.apply(this, arguments); 301 302 if (result.nodeName === "IFRAME") { 303 try { 304 if (result.contentWindow && !result._csrf) { 305 result._csrf = true; 306 handleForm(result.contentWindow.document); 307 } 308 } catch (ex) { 309 if (result.src && result.src.length && verifySameOrigin(result.src)) { 310 if (window.console) { 311 // eslint-disable-next-line no-console 312 console.error("Unable to attach CSRF token to an iframe element on the same origin"); 313 } 314 } 315 316 // Potential error: Access is Denied 317 // we can safely ignore CORS security errors here 318 // because we do not want to expose the csrf anyways to another domain 319 } 320 } 321 322 return result; 323 }; 324 } 325 326 // refreshing csrf token periodically 327 getToken(); 328 329 setInterval(function() { 330 getToken(); 331 }, 300000); 332 333 return {
334 initialised: false, 335 refreshToken: getToken, 336 _clearToken: clearToken 337 }; 338})); 339
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.