| 1 |
/** |
| 2 |
* The auth token the authentication route returns after a successful login. |
| 3 |
* |
| 4 |
* Inside a cross-site iframe the browser drops the WordPress login cookie, so |
| 5 |
* this token is what keeps the donor signed in for the validate and donate |
| 6 |
* requests. It is request transport, not form data: keeping it out of the form |
| 7 |
* values keeps it out of the client-side validation schema, which rejects keys |
| 8 |
* it does not know. |
| 9 |
* |
| 10 |
* It lives on window.givewp.form because the login template and the form app |
| 11 |
* ship in separate bundles, so module state would not be shared between them. |
| 12 |
* |
| 13 |
* @since 4.17.0 |
| 14 |
*/ |
| 15 |
export function setAuthToken(token: string): void { |
| 16 |
window.givewp.form.authToken = token ?? ''; |
| 17 |
} |
| 18 |
|
| 19 |
/** |
| 20 |
* @since 4.17.0 |
| 21 |
*/ |
| 22 |
export function getAuthToken(): string { |
| 23 |
return window.givewp?.form?.authToken ?? ''; |
| 24 |
} |
| 25 |
|