| 1 |
import { trimTrailingChar } from './text' |
| 2 |
import type { AxiosRequestConfig, InternalAxiosRequestConfig } from 'axios' |
| 3 |
|
| 4 |
const normalizeUrl = (url: string | undefined) => |
| 5 |
trimTrailingChar(url ?? '', '/') |
| 6 |
|
| 7 |
export const REST_BASES = { |
| 8 |
snippets: normalizeUrl(window.CODE_SNIPPETS?.restAPI.snippets), |
| 9 |
recentlyActive: normalizeUrl(window.CODE_SNIPPETS?.restAPI.recentlyActive), |
| 10 |
preferences: normalizeUrl(window.CODE_SNIPPETS?.restAPI.preferences), |
| 11 |
importPlugins: normalizeUrl(window.CODE_SNIPPETS?.restAPI.importPlugins), |
| 12 |
importFiles: normalizeUrl(window.CODE_SNIPPETS?.restAPI.importFiles), |
| 13 |
cloud: { |
| 14 |
snippets: normalizeUrl(window.CODE_SNIPPETS?.restAPI.cloud.snippets), |
| 15 |
} |
| 16 |
} |
| 17 |
|
| 18 |
/** Verbs that hosts and firewalls commonly reject outright. */ |
| 19 |
const OVERRIDDEN_METHODS = ['delete', 'put', 'patch'] |
| 20 |
|
| 21 |
/** |
| 22 |
* Send write requests as POST, naming the intended verb in a header. |
| 23 |
* |
| 24 |
* Plenty of hosts allow only GET and POST, so a DELETE never reaches |
| 25 |
* WordPress: the request is rejected upstream, and the browser reports a 403 — |
| 26 |
* or a severed connection — that no amount of correct authentication can fix. |
| 27 |
* The REST server reads `X-HTTP-Method-Override` on a POST and dispatches the |
| 28 |
* route exactly as it would have, so this changes nothing WordPress sees while |
| 29 |
* letting the request through. |
| 30 |
*/ |
| 31 |
export const applyMethodOverride = (config: InternalAxiosRequestConfig): InternalAxiosRequestConfig => { |
| 32 |
const method = config.method?.toLowerCase() |
| 33 |
|
| 34 |
if (!method || !OVERRIDDEN_METHODS.includes(method)) { |
| 35 |
return config |
| 36 |
} |
| 37 |
|
| 38 |
config.headers.set('X-HTTP-Method-Override', method.toUpperCase()) |
| 39 |
config.method = 'post' |
| 40 |
|
| 41 |
return config |
| 42 |
} |
| 43 |
|
| 44 |
export const REST_API_AXIOS_CONFIG: AxiosRequestConfig = { |
| 45 |
headers: { |
| 46 |
'X-WP-Nonce': window.CODE_SNIPPETS?.restAPI.nonce, |
| 47 |
'Access-Control': window.CODE_SNIPPETS?.restAPI.cloud.token |
| 48 |
} |
| 49 |
} |
| 50 |
|