From 27d915c45ed8bd0cf819bb86e68e827f6fde6d0b Mon Sep 17 00:00:00 2001 From: Louis Date: Wed, 16 Sep 2026 12:24:58 +0200 Subject: [PATCH] Fix drag-and-drop reorder: CSRF token was never readable by JS NetBox sets CSRF_COOKIE_HTTPONLY = True, so document.cookie can never see the csrftoken cookie - elevation.js's reorder POST always sent an empty X-CSRFToken header, Django's CSRF middleware rejected every request with 403 before it reached the view, and the JS's failure path (removeAttribute('transform') + a small status message) made a dragged device silently snap back to its old position on every single attempt, not just occasionally. Render {% csrf_token %} on the concept detail page and read the token from that hidden input instead of the cookie - the standard approach for a plain fetch() POST outside of a form. Co-Authored-By: Claude Sonnet 5 --- netbox_rack_concept/static/netbox_rack_concept/elevation.js | 6 ++++-- .../templates/netbox_rack_concept/rackconcept.html | 4 ++++ 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/netbox_rack_concept/static/netbox_rack_concept/elevation.js b/netbox_rack_concept/static/netbox_rack_concept/elevation.js index a44bf8d..58671db 100644 --- a/netbox_rack_concept/static/netbox_rack_concept/elevation.js +++ b/netbox_rack_concept/static/netbox_rack_concept/elevation.js @@ -76,8 +76,10 @@ const statusEl = document.getElementById('concept-elevation-status'); function csrfToken() { - const match = document.cookie.match(/(^|;)\s*csrftoken\s*=\s*([^;]+)/); - return match ? decodeURIComponent(match[2]) : ''; + // NetBox sets CSRF_COOKIE_HTTPONLY, so the cookie itself is invisible to + // JavaScript - read the value from the hidden {% csrf_token %} input instead. + const input = document.querySelector('input[name="csrfmiddlewaretoken"]'); + return input ? input.value : ''; } function setStatus(message, isError) { diff --git a/netbox_rack_concept/templates/netbox_rack_concept/rackconcept.html b/netbox_rack_concept/templates/netbox_rack_concept/rackconcept.html index 5baf80f..08f6436 100644 --- a/netbox_rack_concept/templates/netbox_rack_concept/rackconcept.html +++ b/netbox_rack_concept/templates/netbox_rack_concept/rackconcept.html @@ -143,6 +143,10 @@
+ {# CSRF_COOKIE_HTTPONLY is on in NetBox, so the elevation.js reorder POST can't + read the csrftoken cookie via document.cookie - it reads this hidden input's + value instead, the standard Django way to CSRF-protect a plain fetch(). #} + {% csrf_token %}