Fix drag-and-drop reorder: CSRF token was never readable by JS
NetBox sets CSRF_COOKIE_HTTPONLY = True, so document.cookie can never
see the csrftoken cookie - elevation.js's reorder POST always sent an
empty X-CSRFToken header, Django's CSRF middleware rejected every
request with 403 before it reached the view, and the JS's failure
path (removeAttribute('transform') + a small status message) made a
dragged device silently snap back to its old position on every single
attempt, not just occasionally.
Render {% csrf_token %} on the concept detail page and read the token
from that hidden input instead of the cookie - the standard approach
for a plain fetch() POST outside of a form.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -76,8 +76,10 @@
|
||||
const statusEl = document.getElementById('concept-elevation-status');
|
||||
|
||||
function csrfToken() {
|
||||
const match = document.cookie.match(/(^|;)\s*csrftoken\s*=\s*([^;]+)/);
|
||||
return match ? decodeURIComponent(match[2]) : '';
|
||||
// NetBox sets CSRF_COOKIE_HTTPONLY, so the cookie itself is invisible to
|
||||
// JavaScript - read the value from the hidden {% csrf_token %} input instead.
|
||||
const input = document.querySelector('input[name="csrfmiddlewaretoken"]');
|
||||
return input ? input.value : '';
|
||||
}
|
||||
|
||||
function setStatus(message, isError) {
|
||||
|
||||
Reference in New Issue
Block a user