| @@ -1907,8 +1907,24 @@ | ||
| 1907 | 1907 | password: password, |
| 1908 | 1908 | confirm_password: confirmPassword |
| 1909 | 1909 | }; |
| 1910 | 1910 | |
| 1911 | + // reCAPTCHA v3: this form posts straight to /auth/register, so it must | |
| 1912 | + // carry its own token when the operator protects registration — the | |
| 1913 | + // server rejects an empty one outright, whatever the score threshold. | |
| 1914 | + // Resolves to '' when reCAPTCHA is off or unavailable, so the normal | |
| 1915 | + // (unprotected) flow is completely unchanged. | |
| 1916 | + const yatraRcReg = window.yatraRecaptcha; | |
| 1917 | + const regTokenPromise = (yatraRcReg && typeof yatraRcReg.protects === 'function' | |
| 1918 | + && yatraRcReg.protects('registration') && typeof yatraRcReg.execute === 'function') | |
| 1919 | + ? yatraRcReg.execute('registration') | |
| 1920 | + : Promise.resolve(''); | |
| 1921 | + | |
| 1922 | + regTokenPromise.catch(function () { return ''; }).then(function (regToken) { | |
| 1923 | + if (regToken) { | |
| 1924 | + registerData.recaptcha_token = regToken; | |
| 1925 | + } | |
| 1926 | + | |
| 1911 | 1927 | fetch(apiUrl + '/auth/register', { |
| 1912 | 1928 | method: 'POST', |
| 1913 | 1929 | headers: { |
| 1914 | 1930 | 'Content-Type': 'application/json', |
| @@ -1972,8 +1988,9 @@ | ||
| 1972 | 1988 | $btn.prop('disabled', false); |
| 1973 | 1989 | $btnText.show(); |
| 1974 | 1990 | $btnLoading.hide(); |
| 1975 | 1991 | }); |
| 1992 | + }); // end reCAPTCHA token wrapper | |
| 1976 | 1993 | }); |
| 1977 | 1994 | |
| 1978 | 1995 | // --------------------------------------------------------------------- |
| 1979 | 1996 | // Date field picker upgrade (fast year navigation for Date of Birth) |