Rework CSRF: deterministic token from session + self-healing cookie (no more stale 403s)
This commit is contained in:
@@ -5,22 +5,22 @@ export const FILE_BASE = import.meta.env.VITE_API_BASE
|
||||
? import.meta.env.VITE_API_BASE.replace(/\/api$/, '')
|
||||
: '';
|
||||
|
||||
// P5: CSRF token kept in memory only (not localStorage - not sensitive, but avoids stale tokens)
|
||||
let csrfToken = null;
|
||||
|
||||
// Helper: Read CSRF token from cookie (fallback after page reload)
|
||||
// P5: CSRF token — the server derives it deterministically from the session and
|
||||
// self-heals the cookie on every GET. The frontend simply reads the cookie fresh
|
||||
// on every request, so memory/cookie can never drift apart (no more 403s).
|
||||
function getCSRFTokenFromCookie() {
|
||||
const match = document.cookie.match(/workflow_csrf=([^;]+)/);
|
||||
return match ? match[1] : null;
|
||||
}
|
||||
|
||||
export function setCSRFToken(token) {
|
||||
csrfToken = token;
|
||||
// Kept for API compatibility; the cookie is the single source of truth now.
|
||||
// No-op: token is always read fresh from the cookie.
|
||||
}
|
||||
|
||||
export function getCSRFToken() {
|
||||
// Return memory token, or fallback to cookie (after page reload)
|
||||
return csrfToken || getCSRFTokenFromCookie();
|
||||
// Always read fresh from the cookie (server keeps it in sync on every GET)
|
||||
return getCSRFTokenFromCookie();
|
||||
}
|
||||
|
||||
// P5: Auth relies on HttpOnly cookie only - no token in localStorage
|
||||
|
||||
Reference in New Issue
Block a user