1/* turnstile-guard.js (anti-forgery guard for internal product AJAX) 2 * 3 * NOTE: the filename is kept for deploy stability; this no longer uses Cloudflare 4 * Turnstile. GetVariant / GetDims are INTERNAL endpoints - only ever called by our 5 * own product-page JavaScript. The server gates them with 6 * [ValidateAjaxAntiForgeryToken], which requires the per-session anti-forgery token 7 * that exists ONLY because the visitor loaded one of our pages (rendered by 8 * @Html.AntiForgeryToken()). This helper reads that token from the page and attaches 9 * it as the RequestVerificationToken header, so: 10 * 11 * - a legitimate in-page call ALWAYS carries the token -> passes, zero friction; 12 * - a direct/external scrape (no token, no matching session cookie) -> 403. 13 * 14 * jQuery already sends X-Requested-With: XMLHttpRequest as a cheap extra signal. 15 * There is NO human challenge: customers never see anything. 16 * 17 * Exposes window.tuGuardedAjax(options) - a drop-in for $.ajax that returns the 18 * same jqXHR/thenable, so existing .then()/.catch()/await call sites are unchanged. 19 * 20 * Dependencies: jQuery (loaded globally before this script). 21 */ 22(function (window) { 23 'use strict'; 24 25 // Read the MVC anti-forgery token rendered by @Html.AntiForgeryToken(). 26 // Read at call time (not load time) so it is always the current page's token. 27 function antiForgeryToken() { 28 var el = document.querySelector('input[name="__RequestVerificationToken"]'); 29 return el ? el.value : ''; 30 } 31 32 // Drop-in replacement for $.ajax that attaches the anti-forgery header. 33 function tuGuardedAjax(options) { 34 options = options || {}; 35 var token = antiForgeryToken(); 36 if (token) { 37 options.headers = options.headers || {}; 38 // Don't clobber an explicit header the caller already set. 39 if (!('RequestVerificationToken' in options.headers)) { 40 options.headers.RequestVerificationToken = token; 41 } 42 } 43 return $.ajax(options); 44 } 45 46 window.tuGuardedAjax = tuGuardedAjax; 47 48}(window));
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.