2020-03-19 11:50:51 +00:00
|
|
|
/**
|
|
|
|
* External dependencies
|
|
|
|
*/
|
|
|
|
import apiFetch from '@wordpress/api-fetch';
|
|
|
|
|
2021-02-01 17:09:18 +00:00
|
|
|
// Stores the current nonce for the middleware.
|
|
|
|
let currentNonce = '';
|
|
|
|
let currentTimestamp = 0;
|
|
|
|
|
|
|
|
try {
|
|
|
|
const storedNonceValue = window.localStorage.getItem( 'storeApiNonce' );
|
|
|
|
const storedNonce = storedNonceValue ? JSON.parse( storedNonceValue ) : {};
|
|
|
|
currentNonce = storedNonce?.nonce || '';
|
|
|
|
currentTimestamp = storedNonce?.timestamp || 0;
|
|
|
|
} catch {
|
|
|
|
// We can ignore an error from JSON parse.
|
|
|
|
}
|
2020-03-19 11:50:51 +00:00
|
|
|
|
|
|
|
/**
|
2021-04-20 15:44:49 +00:00
|
|
|
* Returns whether or not this is a wc/store API request.
|
2020-03-19 11:50:51 +00:00
|
|
|
*
|
|
|
|
* @param {Object} options Fetch options.
|
|
|
|
*
|
|
|
|
* @return {boolean} Returns true if this is a store request.
|
|
|
|
*/
|
2024-09-13 09:42:21 +00:00
|
|
|
export const isStoreApiRequest = ( options ) => {
|
2020-03-19 11:50:51 +00:00
|
|
|
const url = options.url || options.path;
|
|
|
|
if ( ! url || ! options.method || options.method === 'GET' ) {
|
|
|
|
return false;
|
|
|
|
}
|
2022-02-23 12:00:45 +00:00
|
|
|
return /wc\/store\/v1\//.exec( url ) !== null;
|
2020-03-19 11:50:51 +00:00
|
|
|
};
|
|
|
|
|
2021-02-01 17:09:18 +00:00
|
|
|
/**
|
|
|
|
* Updates the stored nonce within localStorage so it is persisted between page loads.
|
|
|
|
*
|
2022-04-08 13:47:19 +00:00
|
|
|
* @param {string} nonce Incoming nonce string.
|
2021-02-01 17:09:18 +00:00
|
|
|
* @param {number} timestamp Timestamp from server of nonce.
|
|
|
|
*/
|
|
|
|
const updateNonce = ( nonce, timestamp ) => {
|
|
|
|
// If the "new" nonce matches the current nonce, we don't need to update.
|
|
|
|
if ( nonce === currentNonce ) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
// Only update the nonce if newer. It might be coming from cache.
|
|
|
|
if ( currentTimestamp && timestamp < currentTimestamp ) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
currentNonce = nonce;
|
|
|
|
currentTimestamp = timestamp || Date.now() / 1000; // Convert ms to seconds to match php time()
|
|
|
|
|
|
|
|
// Update the persisted values.
|
|
|
|
window.localStorage.setItem(
|
|
|
|
'storeApiNonce',
|
|
|
|
JSON.stringify( {
|
|
|
|
nonce: currentNonce,
|
|
|
|
timestamp: currentTimestamp,
|
|
|
|
} )
|
|
|
|
);
|
|
|
|
};
|
|
|
|
|
2023-12-12 23:05:20 +00:00
|
|
|
/**
|
|
|
|
* Set the current nonce from a header object.
|
|
|
|
*
|
|
|
|
* @param {Object} headers Headers object.
|
|
|
|
*/
|
|
|
|
const setNonce = ( headers ) => {
|
|
|
|
const nonce =
|
|
|
|
typeof headers?.get === 'function'
|
|
|
|
? headers.get( 'Nonce' )
|
|
|
|
: headers.Nonce;
|
|
|
|
const timestamp =
|
|
|
|
typeof headers?.get === 'function'
|
|
|
|
? headers.get( 'Nonce-Timestamp' )
|
|
|
|
: headers[ 'Nonce-Timestamp' ];
|
|
|
|
|
|
|
|
if ( nonce ) {
|
|
|
|
updateNonce( nonce, timestamp );
|
|
|
|
}
|
|
|
|
};
|
|
|
|
|
2021-04-20 15:44:49 +00:00
|
|
|
const appendNonceHeader = ( request ) => {
|
|
|
|
const headers = request.headers || {};
|
|
|
|
request.headers = {
|
|
|
|
...headers,
|
2022-03-11 12:07:08 +00:00
|
|
|
Nonce: currentNonce,
|
2021-04-20 15:44:49 +00:00
|
|
|
};
|
|
|
|
return request;
|
|
|
|
};
|
|
|
|
|
2020-03-19 11:50:51 +00:00
|
|
|
/**
|
2021-04-20 15:44:49 +00:00
|
|
|
* Nonce middleware which appends the current nonce to store API requests.
|
2020-03-19 11:50:51 +00:00
|
|
|
*
|
|
|
|
* @param {Object} options Fetch options.
|
|
|
|
* @param {Function} next The next middleware or fetchHandler to call.
|
|
|
|
* @return {*} The evaluated result of the remaining middleware chain.
|
|
|
|
*/
|
2020-03-27 20:56:48 +00:00
|
|
|
const storeNonceMiddleware = ( options, next ) => {
|
2021-04-20 15:44:49 +00:00
|
|
|
if ( isStoreApiRequest( options ) ) {
|
|
|
|
options = appendNonceHeader( options );
|
|
|
|
|
|
|
|
// Add nonce to sub-requests
|
|
|
|
if ( Array.isArray( options?.data?.requests ) ) {
|
2022-06-15 09:56:52 +00:00
|
|
|
options.data.requests =
|
|
|
|
options.data.requests.map( appendNonceHeader );
|
2021-04-20 15:44:49 +00:00
|
|
|
}
|
2020-03-19 11:50:51 +00:00
|
|
|
}
|
|
|
|
return next( options, next );
|
|
|
|
};
|
|
|
|
|
|
|
|
apiFetch.use( storeNonceMiddleware );
|
|
|
|
apiFetch.setNonce = setNonce;
|
2021-02-01 17:09:18 +00:00
|
|
|
|
2021-04-22 11:37:27 +00:00
|
|
|
updateNonce(
|
2023-12-12 23:05:20 +00:00
|
|
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
2021-04-22 11:37:27 +00:00
|
|
|
// @ts-ignore wcBlocksMiddlewareConfig is window global cache for the initial nonce initialized from hydration.
|
|
|
|
wcBlocksMiddlewareConfig.storeApiNonce,
|
2023-12-12 23:05:20 +00:00
|
|
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
2021-04-22 11:37:27 +00:00
|
|
|
// @ts-ignore wcBlocksMiddlewareConfig is window global cache for the initial nonce initialized from hydration.
|
|
|
|
wcBlocksMiddlewareConfig.storeApiNonceTimestamp
|
|
|
|
);
|