PageSourceSearch

https://app.trenerbiegania.pl/assets/controllers/csrf_protection_controller-6q_R9-E.js

js trenerbiegania.pl collected 2026-09-26 04:36:18 UTC 3,347 bytes, 81 lines download raw bytes

1const nameCheck = /^[-_a-zA-Z0-9]{4,22}$/;
2const tokenCheck = /^[-_/+a-zA-Z0-9]{24,}$/;
3
4// Generate and double-submit a CSRF token in a form field and a cookie, as defined by Symfony's SameOriginCsrfTokenManager
5// Use `form.requestSubmit()` to ensure that the submit event is triggered. Using `form.submit()` will not trigger the event
6// and thus this event-listener will not be executed.
7document.addEventListener('submit', function (event) {
8    generateCsrfToken(event.target);
9}, true);
10
11// When @hotwired/turbo handles form submissions, send the CSRF token in a header in addition to a cookie
12// The `framework.csrf_protection.check_header` config option needs to be enabled for the header to be checked
13document.addEventListener('turbo:submit-start', function (event) {
14    const h = generateCsrfHeaders(event.detail.formSubmission.formElement);
15    Object.keys(h).map(function (k) {
16        event.detail.formSubmission.fetchRequest.headers[k] = h[k];
17    });
18});
19
20// When @hotwired/turbo handles form submissions, remove the CSRF cookie once a form has been submitted
21document.addEventListener('turbo:submit-end', function (event) {
22    removeCsrfToken(event.detail.formSubmission.formElement);
23});
24
25export function generateCsrfToken (formElement) {
26    const csrfField = formElement.querySelector('input[data-controller="csrf-protection"], input[name="_csrf_token"]');
27
28    if (!csrfField) {
29        return;
30    }
31
32    let csrfCookie = csrfField.getAttribute('data-csrf-protection-cookie-value');
33    let csrfToken = csrfField.value;
34
35    if (!csrfCookie && nameCheck.test(csrfToken)) {
36        csrfField.setAttribute('data-csrf-protection-cookie-value', csrfCookie = csrfToken);
37        csrfField.defaultValue = csrfToken = btoa(String.fromCharCode.apply(null, (window.crypto || window.msCrypto).getRandomValues(new Uint8Array(18))));
38    }
39    csrfField.dispatchEvent(new Event('change', { bubbles: true }));
40
41    if (csrfCookie && tokenCheck.test(csrfToken)) {
42        const cookie = csrfCookie + '_' + csrfToken + '=' + csrfCookie + '; path=/; samesite=strict';
43        document.cookie = window.location.protocol === 'https:' ? '__Host-' + cookie + '; secure' : cookie;
44    }
45}
46
47export function generateCsrfHeaders (formElement) {
48    const headers = {};
49    const csrfField = formElement.querySelector('input[data-controller="csrf-protection"], input[name="_csrf_token"]');
50
51    if (!csrfField) {
52        return headers;
53    }
54
55    const csrfCookie = csrfField.getAttribute('data-csrf-protection-cookie-value');
56
57    if (tokenCheck.test(csrfField.value) && nameCheck.test(csrfCookie)) {
58        headers[csrfCookie] = csrfField.value;
59    }
60
61    return headers;
62}
63
64export function removeCsrfToken (formElement) {
65    const csrfField = formElement.querySelector('input[data-controller="csrf-protection"], input[name="_csrf_token"]');
66
67    if (!csrfField) {
68        return;
69    }
70
71    const csrfCookie = csrfField.getAttribute('data-csrf-protection-cookie-value');
72
73    if (tokenCheck.test(csrfField.value) && nameCheck.test(csrfCookie)) {
74        const cookie = csrfCookie + '_' + csrfField.value + '=0; path=/; samesite=strict; max-age=0';
75
76        document.cookie = window.location.protocol === 'https:' ? '__Host-' + cookie + '; secure' : cookie;
77    }
78}
79
80/* stimulusFetch: 'eager' */
81export default 'csrf-protection-controller';

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.