PageSourceSearch

https://casinosanalyzer.ca/build/midori/assets/js/api/secureApiClient.min.js?v=5801963

js casinosanalyzer.ca collected 2026-09-25 23:52:54 UTC 2,795 bytes, 1 lines download raw bytes

1class SecureApiClient{static PUBLIC_API_KEY_HEADER="X-Public-Api-Key";static PUBLIC_API_KEY_COOKIE="public_api_key";static PUBLIC_API_REFRESH_URL="/api/public-api-key/refresh";static base64ToBytes(e){return Uint8Array.from(atob(e),e=>e.charCodeAt(0))}static async sha256Raw(e){const t=(new TextEncoder).encode(e);return window.crypto.subtle.digest("SHA-256",t)}static getCookie(e){const t=document.cookie?document.cookie.split("; "):[];for(const s of t){const[t,...r]=s.split("=");if(t===e)return decodeURIComponent(r.join("=")||"")}return""}static canDecryptSecurePayload(e){return Boolean(e&&window.crypto?.subtle)}static getClientKey(e={}){return e.clientKey||window.PUBLIC_API_KEY||this.getCookie(this.PUBLIC_API_KEY_COOKIE)||""}static async parseJsonSafe(e){if(!1===(e.headers.get("content-type")||"").toLowerCase().includes("application/json"))return null;try{return await e.json()}catch(e){return null}}static async decryptPayload(e,t){const s=await this.sha256Raw(t),r=await window.crypto.subtle.importKey("raw",s,"AES-GCM",!1,["decrypt"]),i=this.base64ToBytes(e.iv),a=this.base64ToBytes(e.tag),c=this.base64ToBytes(e.data),n=new Uint8Array(c.length+a.length);n.set(c,0),n.set(a,c.length);const o=await window.crypto.subtle.decrypt({name:"AES-GCM",iv:i,tagLength:128},r,n);return JSON.parse((new TextDecoder).decode(o))}static async refreshClientKey(e="same-origin"){const t=await fetch(this.PUBLIC_API_REFRESH_URL,{method:"POST",credentials:e});if(!t.ok)return"";const s=(t.headers.get(this.PUBLIC_API_KEY_HEADER)||"").trim();return""!==s?s:this.getCookie(this.PUBLIC_API_KEY_COOKIE)}static async executeSecureRequest({url:e,method:t,headers:s,body:r,credentials:i,shouldSecure:a,clientKey:c}){const n={...s};if(a){if(""===c)throw new Error("Public API key is missing for secure request");n[this.PUBLIC_API_KEY_HEADER]=c}return fetch(e,{method:t,headers:n,body:r,credentials:i})}static async fetch({url:e,method:t="GET",headers:s={},body:r,credentials:i="same-origin",security:a=null}){const c=a||{},n=Boolean(c.requireSecure),o=Boolean(c.scope),u=n||o;let l=this.getClientKey(c);u&&""===l&&(l=await this.refreshClientKey(i));let d=await this.executeSecureRequest({url:e,method:t,headers:s,body:r,credentials:i,shouldSecure:u,clientKey:l});u&&401===d.status&&(l=await this.refreshClientKey(i),""!==l&&(d=await this.executeSecureRequest({url:e,method:t,headers:s,body:r,credentials:i,shouldSecure:u,clientKey:l})));const h=await this.parseJsonSafe(d);if(null===h)throw new Error("Secure API response must be JSON");if(!h?.encrypted||!h?.payload)return h;if(!this.canDecryptSecurePayload(l))throw new Error("Public API key is missing for encrypted response");return this.decryptPayload(h.payload,l)}}const secureApiFetch=e=>SecureApiClient.fetch(e);export{SecureApiClient,secureApiFetch};

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.