1/* 2 * ADOBE CONFIDENTIAL 3 * 4 * Copyright 2012 Adobe Systems Incorporated 5 * All Rights Reserved. 6 * 7 * NOTICE: All information contained herein is, and remains 8 * the property of Adobe Systems Incorporated and its suppliers, 9 * if any. The intellectual and technical concepts contained 10 * herein are proprietary to Adobe Systems Incorporated and its 11 * suppliers and may be covered by U.S. and Foreign Patents, 12 * patents in process, and are protected by trade secret or copyright law. 13 * Dissemination of this information or reproduction of this material 14 * is strictly forbidden unless prior written permission is obtained 15 * from Adobe Systems Incorporated. 16 * 17 */ 18/* global G_IS_HOOKED:false */ 19(function($, window) { 20 "use strict"; 21 22 var http; 23 24 window.Granite = window.Granite || {}; 25 window.Granite.$ = window.Granite.$ || $; 26 27 // for deprecated "shared" support (GRANITE-1602) 28 window._g = window._g || {}; 29 window._g.$ = window._g.$ || $; 30 31 http = Granite.HTTP; 32 33 // necessary global modifications for ajax calls 34 $.ajaxSetup({ 35 externalize: true, 36 encodePath: true, 37 hook: true, 38 beforeSend: function(jqXHR, s) { 39 // s: settings provided by the ajax call or default values 40 if (typeof G_IS_HOOKED === "undefined" || !G_IS_HOOKED(s.url)) { 41 if (s.externalize) { 42 s.url = http.externalize(s.url); 43 } 44 if (s.encodePath) { 45 s.url = http.encodePathOfURI(s.url); 46 } 47 } 48 if (s.hook) { 49 // portlet XHR hook 50 var hook = http.getXhrHook(s.url, s.type, s.data); 51 if (hook) { 52 s.url = hook.url; 53 if (hook.params) { 54 if (s.type.toUpperCase() === "GET") { 55 s.url += "?" + $.param(hook.params); 56 } else { 57 s.data = $.param(hook.params); 58 } 59 } 60 } 61 } 62 }, 63 statusCode: { 64 403: function(jqXHR) { 65 if (jqXHR.getResponseHeader("X-Reason") === "Authentication Failed") { 66 http.handleLoginRedirect(); 67 } 68 } 69 } 70 }); 71 72 $.ajaxSettings.traditional = true; 73}(jQuery, this)); 74 75/* 76 * ADOBE CONFIDENTIAL 77 * 78 * Copyright 2015 Adobe Systems Incorporated 79 * All Rights Reserved. 80 *
81 * NOTICE: All information contained herein is, and remains 82 * the property of Adobe Systems Incorporated and its suppliers, 83 * if any. The intellectual and technical concepts contained 84 * herein are proprietary to Adobe Systems Incorporated and its 85 * suppliers and may be covered by U.S. and Foreign Patents, 86 * patents in process, and are protected by trade secret or copyright law. 87 * Dissemination of this information or reproduction of this material 88 * is strictly forbidden unless prior written permission is obtained 89 * from Adobe Systems Incorporated. 90 * 91 */ 92(function(factory) { 93 "use strict"; 94 95 // GRANITE-22281 Check for multiple initialization 96 if (window.Granite.csrf) { 97 return; 98 } 99 100 window.Granite.csrf = factory(window.Granite.HTTP); 101}(function(http) { 102 "use strict"; 103 104 // AdobePatentID="P5296" 105 106 function Promise() { 107 this._handler = []; 108 } 109 110 Promise.prototype = { 111 then: function(resolveFn, rejectFn) { 112 this._handler.push({ resolve: resolveFn, reject: rejectFn }); 113 }, 114 resolve: function() { 115 this._execute("resolve", arguments); 116 }, 117 reject: function() { 118 this._execute("reject", arguments); 119 }, 120 _execute: function(result, args) { 121 if (this._handler === null) { 122 throw new Error("Promise already completed."); 123 } 124 125 for (var i = 0, ln = this._handler.length; i < ln; i++) { 126 this._handler[i][result].apply(window, args); 127 } 128 129 this.then = function(resolveFn, rejectFn) { 130 (result === "resolve" ? resolveFn : rejectFn).apply(window, args); 131 }; 132 133 this._handler = null; 134 } 135 }; 136 137 function verifySameOrigin(url) { 138 // url could be relative or scheme relative or absolute 139 // host + port 140 var host = document.location.host; 141 var protocol = document.location.protocol; 142 var relativeOrigin = "//" + host; 143 var origin = protocol + relativeOrigin; 144 145 // Allow absolute or scheme relative URLs to same origin 146 return (url === origin || url.slice(0, origin.length + 1) === origin + "/") || 147 (url === relativeOrigin || url.slice(0, relativeOrigin.length + 1) === relativeOrigin + "/") || 148 // or any other URL that isn't scheme relative or absolute i.e relative. 149 !(/^(\/\/|http:|https:).*/.test(url)); 150 } 151 152 var FIELD_NAME = ":cq_csrf_token"; 153 var HEADER_NAME = "CSRF-Token"; 154 var TOKEN_SERVLET = http.externalize("/libs/granite/csrf/token.json"); 155 156 var promise; 157 var globalToken; 158 159 function logFailRequest(error) { 160 if (window.console) { 161 // eslint-disable-next-line no-console 162 console.warn("CSRF data not available;" + 163 "The data may be unavailable by design, such as during non-authenticated requests: " + error); 164 } 165 } 166 167 function getToken() { 168 var localPromise = new Promise(); 169 promise = localPromise; 170 171 var xhr = new XMLHttpRequest(); 172 xhr.onreadystatechange = function() { 173 if (xhr.readyState === 4) { 174 try { 175 var data = JSON.parse(xhr.responseText); 176 globalToken = data.token; 177 localPromise.resolve(globalToken); 178 } catch (ex) { 179 logFailRequest(ex); 180 localPromise.reject(xhr.responseText); 181 } 182 } 183 }; 184 xhr.open("GET", TOKEN_SERVLET, true); 185 xhr.send(); 186 187 return localPromise; 188 } 189 190 function getTokenSync() { 191 var xhr = new XMLHttpRequest(); 192 xhr.open("GET", TOKEN_SERVLET, false); 193 xhr.send(); 194 195 try { 196 return globalToken = JSON.parse(xhr.responseText).token; 197 } catch (ex) { 198 logFailRequest(ex); 199 } 200 } 201 202 function clearToken() { 203 globalToken = undefined; 204 getToken(); 205 } 206 207 function addField(form) { 208 var action = form.getAttribute("action"); 209 if (form.method.toUpperCase() === "GET" || (action && !verifySameOrigin(action))) { 210 return; 211 } 212 213 if (!globalToken) { 214 getTokenSync(); 215 } 216 217 if (!globalToken) { 218 return; 219 } 220 221 var input = form.querySelector('input[name="' + FIELD_NAME + '"]'); 222 223 if (!input) { 224 input = document.createElement("input"); 225 input.setAttribute("type", "hidden"); 226 input.setAttribute("name", FIELD_NAME); 227 form.appendChild(input); 228 } 229 230 input.setAttribute("value", globalToken); 231 } 232 233 function handleForm(document) { 234 var handler = function(ev) { 235 var t = ev.target; 236 237 if (t.nodeName === "FORM") { 238 addField(t); 239 } 240 }; 241 242 if (document.addEventListener) { 243 document.addEventListener("submit", handler, true); 244 } else if (document.attachEvent) { 245 document.attachEvent("submit", handler); 246 } 247 } 248 249 handleForm(document); 250 251 var open = XMLHttpRequest.prototype.open; 252 253 XMLHttpRequest.prototype.open = function(method, url, async) { 254 if (method.toLowerCase() !== "get" && verifySameOrigin(url)) { 255 this._csrf = true; 256 this._async = async; 257 } 258 259 return open.apply(this, arguments); 260 }; 261 262 var send = XMLHttpRequest.prototype.send; 263 264 XMLHttpRequest.prototype.send = function() { 265 if (!this._csrf) { 266 send.apply(this, arguments); 267 return; 268 } 269 270 if (globalToken) { 271 this.setRequestHeader(HEADER_NAME, globalToken); 272 send.apply(this, arguments); 273 return; 274 } 275 276 if (this._async === false) { 277 getTokenSync(); 278 279 if (globalToken) { 280 this.setRequestHeader(HEADER_NAME, globalToken); 281 } 282 283 send.apply(this, arguments); 284 return; 285 } 286 287 var self = this; 288 var args = Array.prototype.slice.call(arguments); 289 290 promise.then(function(token) { 291 self.setRequestHeader(HEADER_NAME, token); 292 send.apply(self, args); 293 }, function() { 294 send.apply(self, args); 295 }); 296 }; 297 298 var submit = HTMLFormElement.prototype.submit; 299 300 HTMLFormElement.prototype.submit = function() { 301 addField(this); 302 return submit.apply(this, arguments); 303 }; 304 305 if (window.Node) { 306 var ac = Node.prototype.appendChild; 307 308 Node.prototype.appendChild = function() { 309 var result = ac.apply(this, arguments); 310 311 if (result.nodeName === "IFRAME") { 312 try { 313 if (result.contentWindow && !result._csrf) { 314 result._csrf = true; 315 handleForm(result.contentWindow.document); 316 } 317 } catch (ex) { 318 if (result.src && result.src.length && verifySameOrigin(result.src)) { 319 if (window.console) { 320 // eslint-disable-next-line no-console 321 console.error("Unable to attach CSRF token to an iframe element on the same origin"); 322 } 323 } 324 325 // Potential error: Access is Denied 326 // we can safely ignore CORS security errors here 327 // because we do not want to expose the csrf anyways to another domain 328 } 329 } 330 331 return result; 332 }; 333 } 334 335 // refreshing csrf token periodically 336 getToken(); 337 338 setInterval(function() { 339 getToken(); 340 }, 300000); 341 342 return {
343 initialised: false, 344 refreshToken: getToken, 345 _clearToken: clearToken 346 }; 347})); 348
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.