Fix CSRF token: read from cookie after page reload
This commit is contained in:
@@ -8,12 +8,19 @@ export const FILE_BASE = import.meta.env.VITE_API_BASE
|
|||||||
// P5: CSRF token kept in memory only (not localStorage - not sensitive, but avoids stale tokens)
|
// P5: CSRF token kept in memory only (not localStorage - not sensitive, but avoids stale tokens)
|
||||||
let csrfToken = null;
|
let csrfToken = null;
|
||||||
|
|
||||||
|
// Helper: Read CSRF token from cookie (fallback after page reload)
|
||||||
|
function getCSRFTokenFromCookie() {
|
||||||
|
const match = document.cookie.match(/workflow_csrf=([^;]+)/);
|
||||||
|
return match ? match[1] : null;
|
||||||
|
}
|
||||||
|
|
||||||
export function setCSRFToken(token) {
|
export function setCSRFToken(token) {
|
||||||
csrfToken = token;
|
csrfToken = token;
|
||||||
}
|
}
|
||||||
|
|
||||||
export function getCSRFToken() {
|
export function getCSRFToken() {
|
||||||
return csrfToken;
|
// Return memory token, or fallback to cookie (after page reload)
|
||||||
|
return csrfToken || getCSRFTokenFromCookie();
|
||||||
}
|
}
|
||||||
|
|
||||||
// P5: Auth relies on HttpOnly cookie only - no token in localStorage
|
// P5: Auth relies on HttpOnly cookie only - no token in localStorage
|
||||||
|
|||||||
Reference in New Issue
Block a user