PageSourceSearch

https://www.tooled-up.com/Scripts/turnstile-guard.js

js tooled-up.com collected 2026-09-26 05:41:56 UTC 2,096 bytes, 48 lines download raw bytes

1/* turnstile-guard.js  (anti-forgery guard for internal product AJAX)
2 *
3 * NOTE: the filename is kept for deploy stability; this no longer uses Cloudflare
4 * Turnstile. GetVariant / GetDims are INTERNAL endpoints - only ever called by our
5 * own product-page JavaScript. The server gates them with
6 * [ValidateAjaxAntiForgeryToken], which requires the per-session anti-forgery token
7 * that exists ONLY because the visitor loaded one of our pages (rendered by
8 * @Html.AntiForgeryToken()). This helper reads that token from the page and attaches
9 * it as the RequestVerificationToken header, so:
10 *
11 *   - a legitimate in-page call ALWAYS carries the token  -> passes, zero friction;
12 *   - a direct/external scrape (no token, no matching session cookie) -> 403.
13 *
14 * jQuery already sends X-Requested-With: XMLHttpRequest as a cheap extra signal.
15 * There is NO human challenge: customers never see anything.
16 *
17 * Exposes window.tuGuardedAjax(options) - a drop-in for $.ajax that returns the
18 * same jqXHR/thenable, so existing .then()/.catch()/await call sites are unchanged.
19 *
20 * Dependencies: jQuery (loaded globally before this script).
21 */
22(function (window) {
23    'use strict';
24
25    // Read the MVC anti-forgery token rendered by @Html.AntiForgeryToken().
26    // Read at call time (not load time) so it is always the current page's token.
27    function antiForgeryToken() {
28        var el = document.querySelector('input[name="__RequestVerificationToken"]');
29        return el ? el.value : '';
30    }
31
32    // Drop-in replacement for $.ajax that attaches the anti-forgery header.
33    function tuGuardedAjax(options) {
34        options = options || {};
35        var token = antiForgeryToken();
36        if (token) {
37            options.headers = options.headers || {};
38            // Don't clobber an explicit header the caller already set.
39            if (!('RequestVerificationToken' in options.headers)) {
40                options.headers.RequestVerificationToken = token;
41            }
42        }
43        return $.ajax(options);
44    }
45
46    window.tuGuardedAjax = tuGuardedAjax;
47
48}(window));

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.