PageSourceSearch

https://brokensecrets.com/_static/??/wp-content/js/rlt-proxy.js,/w…/js/cmp/v2/cmp-non-gdpr.js?m=1780567333j

js brokensecrets.com collected 2026-10-02 06:25:19 UTC 6,385 bytes, 200 lines download raw bytes

1// listen for rlt authentication events and pass them to children of this document.
2( function() {
3	var currentToken;
4	var parentOrigin;
5	var iframeOrigins;
6	var registeredIframes = [];
7	var initializationListeners = [];
8	var hasBeenInitialized = false;
9	var RLT_KEY = 'jetpack:wpcomRLT';
10
11	// should we inject RLT into this iframe?
12	function rltShouldAuthorizeIframe( frameOrigin ) {
13		if ( ! Array.isArray( iframeOrigins ) ) {
14			return false;
15		}
16		return iframeOrigins.includes( frameOrigin );
17	}
18
19	function rltInvalidateWindowToken( token, target, origin ) {
20		if ( target && typeof target.postMessage === 'function' ) {
21			try {
22				target.postMessage( JSON.stringify( {
23					type: 'rltMessage',
24					data: {
25						event: 'invalidate',
26						token: token,
27						sourceOrigin: window.location.origin,
28					},
29				} ), origin );
30			} catch ( err ) {
31				return;
32			}
33		}
34	}
35
36	/**
37	 * PUBLIC METHODS
38	 */
39	window.rltInvalidateToken = function( token, sourceOrigin ) {
40		// invalidate in current context
41		if ( token === currentToken ) {
42			currentToken = null;
43		}
44
45		// remove from localstorage, but only if in a top level window, not iframe
46		try {
47			if ( window.location === window.parent.location && window.localStorage ) {
48				if ( window.localStorage.getItem(RLT_KEY) === token ) {
49					window.localStorage.removeItem(RLT_KEY);
50				}
51			}
52		} catch( e ) {
53			console.info("localstorage access for invalidate denied - probably blocked third-party access", window.location.href);
54		}
55
56		// invalidate in registered iframes
57		for ( const [ frameOrigin, frameWindow ] of registeredIframes ) {
58			if ( frameOrigin !== sourceOrigin ) {
59				rltInvalidateWindowToken( token, frameWindow, frameOrigin );
60			}
61		}
62
63		// invalidate in parent
64		if ( parentOrigin && parentOrigin !== sourceOrigin && window.parent ) {
65			rltInvalidateWindowToken( token, window.parent, parentOrigin );
66		}
67	}
68
69	window.rltInjectToken = function( token, target, origin ) {
70		if ( target && typeof target.postMessage === 'function' ) {
71			try {
72				target.postMessage( JSON.stringify( {
73					type: 'loginMessage',
74					data: {
75						event: 'login',
76						success: true,
77						type: 'rlt',
78						token: token,
79						sourceOrigin: window.location.origin,
80					},
81				} ), origin );
82			} catch ( err ) {
83				return;
84			}
85		}
86	};
87
88	window.rltIsAuthenticated = function() {
89		return !! currentToken;
90	};
91
92	window.rltGetToken = function() {
93		return currentToken;
94	};
95
96	window.rltAddInitializationListener = function( listener ) {
97		// if RLT is already initialized, call the listener immediately
98		if ( hasBeenInitialized ) {
99			listener( currentToken );
100		} else {
101			initializationListeners.push( listener );
102		}
103	};
104
105	// store the token in localStorage
106	window.rltStoreToken = function( token ) {
107		currentToken = token;
108		try {
109			if ( window.location === window.parent.location && window.localStorage ) {
110				window.localStorage.setItem( RLT_KEY, token );
111			}
112		} catch( e ) {
113			console.info("localstorage access denied - probably blocked third-party access", window.location.href);
114		}
115	}
116
117	window.rltInitialize = function( config ) {
118		if ( ! config || typeof window.postMessage !== 'function' ) {
119			return;
120		}
121
122		currentToken  = config.token;
123		iframeOrigins = config.iframeOrigins;
124		parentOrigin  = config.parentOrigin; // needed?
125
126		// load token from localStorage if possible, but only in top level window
127		try {
128			if ( ! currentToken && window.location === window.parent.location && window.localStorage ) {
129				currentToken = window.localStorage.getItem(RLT_KEY);
130			}
131		} catch( e ) {
132			console.info("localstorage access denied - probably blocked third-party access", window.location.href);
133		}
134
135		// listen for RLT events from approved origins
136		window.addEventListener( 'message', function( e ) {
137			var message = e && e.data;
138			if ( typeof message === 'string' ) {
139				try {
140					message = JSON.parse( message );
141				} catch ( err ) {
142					return;
143				}
144			}
145
146			var type = message && message.type;
147			var data = message && message.data;
148
149			if ( type === 'loginMessage' ) {
150				if ( data && data.type === 'rlt' && data.token !== currentToken ) {
151					// put into localStorage if running in top-level window (not iframe)
152					rltStoreToken( data.token );
153
154					// send to registered iframes
155					for ( const [ frameOrigin, frameWindow ] of registeredIframes ) {
156						rltInjectToken( currentToken, frameWindow, frameOrigin );
157					}
158
159					// send to the parent, unless the event was sent _by_ the parent
160					if ( parentOrigin && parentOrigin !== data.sourceOrigin && window.parent ) {
161						rltInjectToken( currentToken, window.parent, parentOrigin );
162					}
163				}
164			}
165
166			if ( type === 'rltMessage' ) {
167				if ( data && data.event === 'invalidate' && data.token === currentToken ) {
168					rltInvalidateToken( data.token );
169				}
170
171				if ( data && data.event === 'register' ) {
172					if ( rltShouldAuthorizeIframe( e.origin ) ) {
173						registeredIframes.push( [ e.origin, e.source ] );
174						if ( currentToken ) {
175							rltInjectToken( currentToken, e.source, e.origin );
176						}
177					}
178				}
179			}
180		} );
181
182		initializationListeners.forEach( function( listener ) {
183			listener( currentToken );
184		} );
185
186		initializationListeners = [];
187
188		// inform the parent that we are ready to receive the RLT token
189		window.parent.postMessage( {
190			type: 'rltMessage',
191			data: {
192				event: 'register'
193			},
194		}, '*' );
195
196		hasBeenInitialized = true;
197	};
198} )();
199;
200!function(){function e(){const e=document.createElement("iframe");e.style.cssText="display:none",e.name="__tcfapiLocator",document.body.appendChild(e)}window.__tcfapi=function(){let e=[].slice.call(arguments),t=e[0],n=e[2];"ping"===t?"function"==typeof n&&n({gdprApplies:!1,cmpLoaded:!1,cmpStatus:"stub",displayStatus:"disabled",apiVersion:"2"}):"getTCData"!==t&&"addEventListener"!==t||"function"==typeof n&&n({gdprApplies:!1,tcfPolicyVersion:5,cmpId:258,cmpVersion:1},!0)},window.addEventListener("message",(function(e){let t="string"==typeof e.data,n={};try{n=t?JSON.parse(e.data):e.data}catch(e){}let a=n.__tcfapiCall;a&&window.__tcfapi(a.command,a.version,(function(n,c){let i={__tcfapiReturn:{returnValue:n,success:c,callId:a.callId}};t&&(i=JSON.stringify(i)),e&&e.source&&e.source.postMessage&&e.source.postMessage(i,"*")}),a.parameter)}),!1),"loading"!==document.readyState?e():document.addEventListener("DOMContentLoaded",e)}();;

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.