1// automatically send CSRF token for all AJAX and POST requests 2 3function addCsrfField(form) { 4 if (form.method.toUpperCase() !== 'GET') { 5 const input = document.createElement('input') 6 input.type = 'hidden' 7 input.name = csrfParam 8 form[csrfParam] || form.append(input) 9 form[csrfParam].value = getCsrfToken() 10 } 11} 12 13function csrf_semua_form() 14{ 15 document.querySelectorAll('form').forEach((form) => { 16 addCsrfField(form) 17 form.addEventListener('submit', (e) => addCsrfField(e.target)) 18 }) 19 20 document.addEventListener('submit', (e) => { 21 if (e.target.nodeName === 'FORM') { 22 addCsrfField(e.target) 23 } 24 }) 25} 26 27$('document').ready(function() { 28 csrf_semua_form(); 29 30 $.ajaxPrefilter((opts, origOpts, xhr) => { 31 if (opts.crossDomain) { 32 return 33 } 34 if (opts.type !== 'GET' && opts.type !== 'PUT') { 35 if (opts.data instanceof FormData) { 36 opts.data.append(csrfParam, getCsrfToken()) 37 } else { 38 opts.data = `${opts.data||''}&${csrfParam}=${getCsrfToken()}` 39 } 40 } 41 }) 42})
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.