|
| 1 | +import ajax from 'devextreme/core/utils/ajax'; |
| 2 | +import { Deferred } from 'devextreme/core/utils/deferred'; |
| 3 | + |
| 4 | +const sendRequestOrig = ajax.sendRequest; |
| 5 | +const fetchOrig = fetch; |
| 6 | +let antiForgeryGettingPromise = null; |
| 7 | + |
| 8 | +async function fetchAntiForgeryToken() { |
| 9 | + try { |
| 10 | + const response = await fetchOrig('https://js.devexpress.com/Demos/NetCore/api/Common/GetAntiForgeryToken', { |
| 11 | + method: 'GET', |
| 12 | + credentials: 'include', |
| 13 | + cache: 'no-cache', |
| 14 | + }); |
| 15 | + |
| 16 | + if (!response.ok) { |
| 17 | + const errorMessage = await response.text(); |
| 18 | + throw new Error(`Failed to retrieve anti-forgery token: ${errorMessage || response.statusText}`); |
| 19 | + } |
| 20 | + |
| 21 | + return await response.json(); |
| 22 | + } catch (error) { |
| 23 | + const errorMessage = error instanceof Error ? error.message : 'Unknown error'; |
| 24 | + throw new Error(errorMessage); |
| 25 | + } |
| 26 | +} |
| 27 | + |
| 28 | +async function getAntiForgeryTokenValue() { |
| 29 | + const tokenMeta = document.querySelector('meta[name="csrf-token"]'); |
| 30 | + |
| 31 | + if (tokenMeta) { |
| 32 | + const headerName = tokenMeta.dataset.headerName || 'RequestVerificationToken'; |
| 33 | + const token = tokenMeta.getAttribute('content') || ''; |
| 34 | + |
| 35 | + return Promise.resolve({ headerName, token }); |
| 36 | + } |
| 37 | + |
| 38 | + if (!antiForgeryGettingPromise) { |
| 39 | + antiForgeryGettingPromise = fetchAntiForgeryToken(); |
| 40 | + } |
| 41 | + |
| 42 | + const tokenData = await antiForgeryGettingPromise; |
| 43 | + const meta = document.createElement('meta'); |
| 44 | + |
| 45 | + meta.name = 'csrf-token'; |
| 46 | + meta.content = tokenData.token; |
| 47 | + meta.dataset.headerName = tokenData.headerName; |
| 48 | + document.head.appendChild(meta); |
| 49 | + antiForgeryGettingPromise = null; |
| 50 | + |
| 51 | + return tokenData; |
| 52 | +} |
| 53 | + |
| 54 | +ajax.sendRequest = (options) => { |
| 55 | + const deferred = typeof Deferred !== 'undefined' ? new Deferred() : (() => { |
| 56 | + let resolve; |
| 57 | + let reject; |
| 58 | + // eslint-disable-next-line spellcheck/spell-checker |
| 59 | + const promise = new Promise((res, rej) => { resolve = res; reject = rej; }); |
| 60 | + return { promise: () => promise, resolve, reject }; |
| 61 | + })(); |
| 62 | + |
| 63 | + getAntiForgeryTokenValue().then(({ headerName, token }) => { |
| 64 | + options.headers = { |
| 65 | + [headerName]: token, |
| 66 | + ...(options.headers || {}), |
| 67 | + }; |
| 68 | + |
| 69 | + options.xhrFields = { |
| 70 | + withCredentials: true, |
| 71 | + }; |
| 72 | + |
| 73 | + sendRequestOrig(options).then( |
| 74 | + (result) => { |
| 75 | + deferred.resolve(result); |
| 76 | + if (result.success) { |
| 77 | + deferred.resolve(result); |
| 78 | + } else { |
| 79 | + deferred.reject(result); |
| 80 | + } |
| 81 | + }, |
| 82 | + (e) => deferred.reject(e), |
| 83 | + ); |
| 84 | + }); |
| 85 | + |
| 86 | + return deferred.promise(); |
| 87 | +}; |
| 88 | + |
| 89 | +window.fetch = async (url, options = {}) => { |
| 90 | + const { headerName, token } = await getAntiForgeryTokenValue(); |
| 91 | + |
| 92 | + options.headers = { |
| 93 | + [headerName]: token, |
| 94 | + ...(options.headers || {}), |
| 95 | + }; |
| 96 | + |
| 97 | + options.credentials = 'include'; |
| 98 | + |
| 99 | + return fetchOrig(url, options); |
| 100 | +}; |
0 commit comments