1// listen for rlt authentication events and pass them to children of this document. 2( function() { 3 var currentToken; 4 var parentOrigin; 5 var iframeOrigins; 6 var registeredIframes = []; 7 var initializationListeners = []; 8 var hasBeenInitialized = false; 9 var RLT_KEY = 'jetpack:wpcomRLT'; 10 11 // should we inject RLT into this iframe? 12 function rltShouldAuthorizeIframe( frameOrigin ) { 13 if ( ! Array.isArray( iframeOrigins ) ) { 14 return false; 15 } 16 return iframeOrigins.includes( frameOrigin ); 17 } 18 19 function rltInvalidateWindowToken( token, target, origin ) { 20 if ( target && typeof target.postMessage === 'function' ) { 21 try { 22 target.postMessage( JSON.stringify( { 23 type: 'rltMessage', 24 data: { 25 event: 'invalidate', 26 token: token, 27 sourceOrigin: window.location.origin, 28 }, 29 } ), origin ); 30 } catch ( err ) { 31 return; 32 } 33 } 34 } 35 36 /** 37 * PUBLIC METHODS 38 */ 39 window.rltInvalidateToken = function( token, sourceOrigin ) { 40 // invalidate in current context 41 if ( token === currentToken ) { 42 currentToken = null; 43 } 44 45 // remove from localstorage, but only if in a top level window, not iframe 46 try { 47 if ( window.location === window.parent.location && window.localStorage ) { 48 if ( window.localStorage.getItem(RLT_KEY) === token ) { 49 window.localStorage.removeItem(RLT_KEY); 50 } 51 } 52 } catch( e ) { 53 console.info("localstorage access for invalidate denied - probably blocked third-party access", window.location.href); 54 } 55 56 // invalidate in registered iframes 57 for ( const [ frameOrigin, frameWindow ] of registeredIframes ) { 58 if ( frameOrigin !== sourceOrigin ) { 59 rltInvalidateWindowToken( token, frameWindow, frameOrigin ); 60 } 61 } 62 63 // invalidate in parent 64 if ( parentOrigin && parentOrigin !== sourceOrigin && window.parent ) { 65 rltInvalidateWindowToken( token, window.parent, parentOrigin ); 66 } 67 } 68 69 window.rltInjectToken = function( token, target, origin ) { 70 if ( target && typeof target.postMessage === 'function' ) { 71 try { 72 target.postMessage( JSON.stringify( { 73 type: 'loginMessage', 74 data: { 75 event: 'login', 76 success: true, 77 type: 'rlt', 78 token: token, 79 sourceOrigin: window.location.origin, 80 }, 81 } ), origin ); 82 } catch ( err ) { 83 return; 84 } 85 } 86 }; 87 88 window.rltIsAuthenticated = function() { 89 return !! currentToken; 90 }; 91 92 window.rltGetToken = function() { 93 return currentToken; 94 }; 95 96 window.rltAddInitializationListener = function( listener ) { 97 // if RLT is already initialized, call the listener immediately 98 if ( hasBeenInitialized ) { 99 listener( currentToken ); 100 } else { 101 initializationListeners.push( listener ); 102 } 103 }; 104 105 // store the token in localStorage 106 window.rltStoreToken = function( token ) { 107 currentToken = token; 108 try { 109 if ( window.location === window.parent.location && window.localStorage ) { 110 window.localStorage.setItem( RLT_KEY, token ); 111 } 112 } catch( e ) { 113 console.info("localstorage access denied - probably blocked third-party access", window.location.href); 114 } 115 } 116 117 window.rltInitialize = function( config ) { 118 if ( ! config || typeof window.postMessage !== 'function' ) { 119 return; 120 } 121 122 currentToken = config.token; 123 iframeOrigins = config.iframeOrigins; 124 parentOrigin = config.parentOrigin; // needed? 125 126 // load token from localStorage if possible, but only in top level window 127 try { 128 if ( ! currentToken && window.location === window.parent.location && window.localStorage ) { 129 currentToken = window.localStorage.getItem(RLT_KEY); 130 } 131 } catch( e ) { 132 console.info("localstorage access denied - probably blocked third-party access", window.location.href); 133 } 134 135 // listen for RLT events from approved origins 136 window.addEventListener( 'message', function( e ) { 137 var message = e && e.data; 138 if ( typeof message === 'string' ) { 139 try { 140 message = JSON.parse( message ); 141 } catch ( err ) { 142 return; 143 } 144 } 145 146 var type = message && message.type; 147 var data = message && message.data; 148 149 if ( type === 'loginMessage' ) { 150 if ( data && data.type === 'rlt' && data.token !== currentToken ) { 151 // put into localStorage if running in top-level window (not iframe) 152 rltStoreToken( data.token ); 153 154 // send to registered iframes 155 for ( const [ frameOrigin, frameWindow ] of registeredIframes ) { 156 rltInjectToken( currentToken, frameWindow, frameOrigin ); 157 } 158 159 // send to the parent, unless the event was sent _by_ the parent 160 if ( parentOrigin && parentOrigin !== data.sourceOrigin && window.parent ) { 161 rltInjectToken( currentToken, window.parent, parentOrigin ); 162 } 163 } 164 } 165 166 if ( type === 'rltMessage' ) {
167 if ( data && data.event === 'invalidate' && data.token === currentToken ) { 168 rltInvalidateToken( data.token ); 169 } 170 171 if ( data && data.event === 'register' ) { 172 if ( rltShouldAuthorizeIframe( e.origin ) ) { 173 registeredIframes.push( [ e.origin, e.source ] ); 174 if ( currentToken ) { 175 rltInjectToken( currentToken, e.source, e.origin ); 176 } 177 } 178 } 179 } 180 } ); 181 182 initializationListeners.forEach( function( listener ) { 183 listener( currentToken ); 184 } ); 185 186 initializationListeners = []; 187 188 // inform the parent that we are ready to receive the RLT token 189 window.parent.postMessage( { 190 type: 'rltMessage', 191 data: { 192 event: 'register' 193 }, 194 }, '*' ); 195 196 hasBeenInitialized = true; 197 }; 198} )(); 199; 200!function(){function e(){const e=document.createElement("iframe");e.style.cssText="display:none",e.name="__tcfapiLocator",document.body.appendChild(e)}window.__tcfapi=function(){let e=[].slice.call(arguments),t=e[0],n=e[2];"ping"===t?"function"==typeof n&&n({gdprApplies:!1,cmpLoaded:!1,cmpStatus:"stub",displayStatus:"disabled",apiVersion:"2"}):"getTCData"!==t&&"addEventListener"!==t||"function"==typeof n&&n({gdprApplies:!1,tcfPolicyVersion:5,cmpId:258,cmpVersion:1},!0)},window.addEventListener("message",(function(e){let t="string"==typeof e.data,n={};try{n=t?JSON.parse(e.data):e.data}catch(e){}let a=n.__tcfapiCall;a&&window.__tcfapi(a.command,a.version,(function(n,c){let i={__tcfapiReturn:{returnValue:n,success:c,callId:a.callId}};t&&(i=JSON.stringify(i)),e&&e.source&&e.source.postMessage&&e.source.postMessage(i,"*")}),a.parameter)}),!1),"loading"!==document.readyState?e():document.addEventListener("DOMContentLoaded",e)}();;
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.