Fix CSRF token: read from cookie after page reload

This commit is contained in:
Kühn
2026-08-25 12:02:07 +02:00
parent 3e1ac99f38
commit b0fcabe4a5

View File

@@ -8,12 +8,19 @@ export const FILE_BASE = import.meta.env.VITE_API_BASE
// P5: CSRF token kept in memory only (not localStorage - not sensitive, but avoids stale tokens)
let csrfToken = null;
// Helper: Read CSRF token from cookie (fallback after page reload)
function getCSRFTokenFromCookie() {
const match = document.cookie.match(/workflow_csrf=([^;]+)/);
return match ? match[1] : null;
}
export function setCSRFToken(token) {
csrfToken = token;
}
export function getCSRFToken() {
return csrfToken;
// Return memory token, or fallback to cookie (after page reload)
return csrfToken || getCSRFTokenFromCookie();
}
// P5: Auth relies on HttpOnly cookie only - no token in localStorage