1(() => { 2 const original = window.fetch.bind(window); 3 let token = ""; 4 let pending = null; 5 6 function loadToken() { 7 if (token) return Promise.resolve(token); 8 if (pending) return pending; 9 pending = original("/api/csrf", { credentials: "same-origin" }) 10 .then((r) => (r.ok ? r.json() : {})) 11 .then((data) => { 12 token = String(data.token || ""); 13 return token; 14 }) 15 .finally(() => { 16 pending = null; 17 }); 18 return pending; 19 } 20 21 loadToken(); 22 23 window.fetch = function csrfFetch(input, init) { 24 const next = init ? { ...init } : {}; 25 const method = String(next.method || "GET").toUpperCase(); 26 if (method === "POST" || method === "PUT" || method === "PATCH" || method === "DELETE") { 27 return loadToken().then((value) => { 28 const headers = new Headers(next.headers || {}); 29 if (value && !headers.has("X-CSRF-Token")) { 30 headers.set("X-CSRF-Token", value); 31 } 32 next.headers = headers; 33 if (!next.credentials) next.credentials = "same-origin"; 34 return original(input, next); 35 }); 36 } 37 return original(input, next); 38 }; 39})();
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.