Fix drag-and-drop reorder: CSRF token was never readable by JS
NetBox sets CSRF_COOKIE_HTTPONLY = True, so document.cookie can never
see the csrftoken cookie - elevation.js's reorder POST always sent an
empty X-CSRFToken header, Django's CSRF middleware rejected every
request with 403 before it reached the view, and the JS's failure
path (removeAttribute('transform') + a small status message) made a
dragged device silently snap back to its old position on every single
attempt, not just occasionally.
Render {% csrf_token %} on the concept detail page and read the token
from that hidden input instead of the cookie - the standard approach
for a plain fetch() POST outside of a form.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -76,8 +76,10 @@
|
||||
const statusEl = document.getElementById('concept-elevation-status');
|
||||
|
||||
function csrfToken() {
|
||||
const match = document.cookie.match(/(^|;)\s*csrftoken\s*=\s*([^;]+)/);
|
||||
return match ? decodeURIComponent(match[2]) : '';
|
||||
// NetBox sets CSRF_COOKIE_HTTPONLY, so the cookie itself is invisible to
|
||||
// JavaScript - read the value from the hidden {% csrf_token %} input instead.
|
||||
const input = document.querySelector('input[name="csrfmiddlewaretoken"]');
|
||||
return input ? input.value : '';
|
||||
}
|
||||
|
||||
function setStatus(message, isError) {
|
||||
|
||||
@@ -143,6 +143,10 @@
|
||||
</div>
|
||||
</div>
|
||||
<div class="card-body">
|
||||
{# CSRF_COOKIE_HTTPONLY is on in NetBox, so the elevation.js reorder POST can't
|
||||
read the csrftoken cookie via document.cookie - it reads this hidden input's
|
||||
value instead, the standard Django way to CSRF-protect a plain fetch(). #}
|
||||
{% csrf_token %}
|
||||
<div class="d-flex justify-content-around flex-wrap"
|
||||
id="concept-elevations"
|
||||
data-reorder-url="{% url 'plugins:netbox_rack_concept:rackconcept_reorder' pk=object.pk %}"
|
||||
|
||||
Reference in New Issue
Block a user