add CSRF protection for AJAX requests
This commit is contained in:
+7
-1
@@ -167,11 +167,17 @@ document.addEventListener('DOMContentLoaded', function() {
|
||||
url += `&category=${categoryId}`;
|
||||
}
|
||||
|
||||
// Préparer les données avec token CSRF
|
||||
const formData = new FormData();
|
||||
formData.append('csrf_token', document.querySelector('meta[name="csrf-token"]').getAttribute('content'));
|
||||
|
||||
// Faire la requête AJAX
|
||||
fetch(url, {
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'X-Requested-With': 'XMLHttpRequest'
|
||||
}
|
||||
},
|
||||
body: formData
|
||||
})
|
||||
.then(response => response.json())
|
||||
.then(data => {
|
||||
|
||||
Reference in New Issue
Block a user