Admin page: validate key before persisting to sessionStorage (#99)
Panel was already display:none-gated until auth; tightened so a wrong submitted key is never stored in sessionStorage — the typed key is validated via the settings API first, and only persisted on 200.
This commit is contained in:
@@ -44,7 +44,8 @@
|
||||
|
||||
function api(path, opts) {
|
||||
opts = opts || {};
|
||||
opts.headers = { 'X-Admin-Key': key() };
|
||||
// allow callers to override the key header (e.g. validating a typed key, #99)
|
||||
opts.headers = Object.assign({ 'X-Admin-Key': key() }, opts.headers || {});
|
||||
if (opts.body) opts.headers['Content-Type'] = 'application/json';
|
||||
return fetch(path, opts);
|
||||
}
|
||||
@@ -72,9 +73,10 @@
|
||||
|
||||
document.getElementById('admin-key-form').addEventListener('submit', function (e) {
|
||||
e.preventDefault();
|
||||
sessionStorage.setItem(KEY, keyInput.value);
|
||||
api('/admin/api/settings').then(function (r) {
|
||||
// #99: don't persist the key until the server accepts it
|
||||
api('/admin/api/settings', { headers: { 'X-Admin-Key': keyInput.value } }).then(function (r) {
|
||||
if (r.status === 200) {
|
||||
sessionStorage.setItem(KEY, keyInput.value);
|
||||
status.textContent = '✓';
|
||||
keyInput.value = '';
|
||||
loadSettings();
|
||||
|
||||
Reference in New Issue
Block a user