Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions frontend/src/App.jsx
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ import CustomMarkdown from "./components/helpers/custom-markdown/CustomMarkdown.
import { NotificationClearAll } from "./components/notification/NotificationClearAll.jsx";
import { NotificationIdLine } from "./components/notification/NotificationIdLine.jsx";
import { PageTitle } from "./components/widgets/page-title/PageTitle.jsx";
import { installGlobalCsrfInterceptor } from "./helpers/csrf.js";
import { THEME } from "./helpers/GetStaticData.js";
import { attachRequestIdInterceptor } from "./helpers/requestId.js";
import PostHogPageviewTracker from "./PostHogPageviewTracker.js";
Expand All @@ -26,6 +27,10 @@ if (!axios[GLOBAL_INTERCEPTOR_FLAG]) {
axios[GLOBAL_INTERCEPTOR_FLAG] = true;
}

// The few intentional raw-axios callers (pre-session bootstrap, background log
// writes) get CSRF here; everything else goes through useAxiosPrivate.
installGlobalCsrfInterceptor(axios);

let GoogleTagManagerHelper;
try {
const mod = await import(
Expand Down
6 changes: 0 additions & 6 deletions frontend/src/components/agency/agency/Agency.jsx
Original file line number Diff line number Diff line change
Expand Up @@ -832,13 +832,11 @@ function Agency() {

const handleWfExecutionApi = async (body) => {
let header = {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
};
if (shouldIncludeFile(body) && apiOpsPresent && fileList.length > 0) {
body = getRequestBody(body);
header = {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "multipart/form-data",
};
}
Expand Down Expand Up @@ -939,9 +937,6 @@ function Agency() {
const deleteOptions = {
method: "DELETE",
url: getUrl(`tool_instance/${existingTool.id}/`),
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
},
};
await axiosPrivate(deleteOptions);
}
Expand All @@ -963,7 +958,6 @@ function Agency() {
method: "POST",
url: getUrl(`tool_instance/`),
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: body,
Expand Down
3 changes: 0 additions & 3 deletions frontend/src/components/agency/cards-list/CardsList.jsx
Original file line number Diff line number Diff line change
Expand Up @@ -35,9 +35,6 @@ const CardsList = ({ step, index, activeTool, moveItem }) => {
const requestOptions = {
method: "DELETE",
url: `/api/v1/unstract/${sessionDetails?.orgId}/tool_instance/${toolSettings?.id}/`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
},
};

axiosPrivate(requestOptions)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -141,7 +141,6 @@ function DsSettingsCard({ connType, endpointDetails, message }) {
method: "PATCH",
url: getUrl(`workflow/endpoint/${destination?.id}/`),
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: updatedData,
Expand Down Expand Up @@ -178,7 +177,6 @@ function DsSettingsCard({ connType, endpointDetails, message }) {
method: "PATCH",
url: getUrl(`workflow/endpoint/${endpointDetails?.id}/`),
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: updatedData,
Expand Down
1 change: 0 additions & 1 deletion frontend/src/components/agency/prompt/Prompt.jsx
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,6 @@ function Prompt() {
url: `/api/v1/unstract/${sessionDetails?.orgId}/workflow/${workflowId}/`,
headers: {
"Content-Type": "application/json",
"X-CSRFToken": sessionDetails?.csrfToken,
},
data: body,
};
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -89,7 +89,6 @@ function ToolSettings({ spec, isSpecLoading }) {
url: `/api/v1/unstract/${sessionDetails?.orgId}/tool_instance/${toolSettings?.id}/`,
headers: {
"Content-Type": "application/json",
"X-CSRFToken": sessionDetails?.csrfToken,
},
data: { metadata },
};
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -52,9 +52,6 @@ function AdapterSelectionModal({
const requests = adapterTypes.map((type) =>
fetchAllPages(axiosPrivate, {
url: `/api/v1/unstract/${sessionDetails?.orgId}/adapter/`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
},
params: {
adapter_type: type,
},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -316,7 +316,6 @@ function AddLlmProfile({
method,
url,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: formDetails,
Expand Down Expand Up @@ -391,9 +390,6 @@ function AddLlmProfile({
const requestOptions = {
method: "GET",
url: `/api/v1/unstract/${sessionDetails?.orgId}/adapter/info/${value}/`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
},
};

axiosPrivate(requestOptions)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -211,9 +211,6 @@ function CombinedOutput({ docId, setFilledFields, selectedPrompts }) {
const requestOptions = {
method: "GET",
url,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
},
};
const res = await axiosPrivate(requestOptions);
return res;
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -155,7 +155,6 @@ function CustomDataSettings() {
method: "PATCH",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/${details?.tool_id}/`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: body,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -197,7 +197,6 @@ function CustomSynonyms() {
method: "PATCH",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/${details?.tool_id}/`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: body,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -198,7 +198,6 @@ function DocumentParser({
method: "PATCH",
url,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: body,
Expand Down Expand Up @@ -242,9 +241,6 @@ function DocumentParser({
const requestOptions = {
method: "DELETE",
url,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
},
};

axiosPrivate(requestOptions)
Expand Down
7 changes: 0 additions & 7 deletions frontend/src/components/custom-tools/header/Header.jsx
Original file line number Diff line number Diff line change
Expand Up @@ -92,7 +92,6 @@ function Header({
method: "POST",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/export/${details?.tool_id}`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: body,
Expand Down Expand Up @@ -149,9 +148,6 @@ function Header({
const requestOptions = {
method: "GET",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/export/${details?.tool_id}`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
},
};
setIsExportLoading(true);
getAllUsers().then((users) => {
Expand Down Expand Up @@ -220,9 +216,6 @@ function Header({
const requestOptions = {
method: "GET",
url: downloadUrl,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
},
responseType: "blob",
};

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -99,14 +99,12 @@ function ListOfTools({ segmentOptions, segmentValue, onSegmentChange }) {
axiosPrivate({
method: "GET",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/users/${id}`,
headers: { "X-CSRFToken": sessionDetails?.csrfToken },
}),
addCoOwner: (id, userId) =>
axiosPrivate({
method: "POST",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/${id}/owners/`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: { user_id: userId },
Expand All @@ -115,10 +113,9 @@ function ListOfTools({ segmentOptions, segmentValue, onSegmentChange }) {
axiosPrivate({
method: "DELETE",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/${id}/owners/${userId}/`,
headers: { "X-CSRFToken": sessionDetails?.csrfToken },
}),
}),
[axiosPrivate, sessionDetails?.orgId, sessionDetails?.csrfToken],
[axiosPrivate, sessionDetails?.orgId],
);

const {
Expand Down Expand Up @@ -168,7 +165,6 @@ function ListOfTools({ segmentOptions, segmentValue, onSegmentChange }) {
return axiosPrivate({
method: "GET",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/`,
headers: { "X-CSRFToken": sessionDetails?.csrfToken },
params,
})
.then((res) =>
Expand Down Expand Up @@ -206,7 +202,6 @@ function ListOfTools({ segmentOptions, segmentValue, onSegmentChange }) {
},
[
sessionDetails?.orgId,
sessionDetails?.csrfToken,
axiosPrivate,
setPagination,
setAlertDetails,
Expand Down Expand Up @@ -235,7 +230,6 @@ function ListOfTools({ segmentOptions, segmentValue, onSegmentChange }) {
method,
url,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: body,
Expand Down Expand Up @@ -269,9 +263,6 @@ function ListOfTools({ segmentOptions, segmentValue, onSegmentChange }) {
const requestOptions = {
method: "DELETE",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/${tool.tool_id}`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
},
};

axiosPrivate(requestOptions)
Expand Down Expand Up @@ -325,9 +316,6 @@ function ListOfTools({ segmentOptions, segmentValue, onSegmentChange }) {
const requestOptions = {
method: "POST",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/project-transfer/`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
},
data: formData,
};

Expand Down Expand Up @@ -360,9 +348,6 @@ function ListOfTools({ segmentOptions, segmentValue, onSegmentChange }) {
const requestOptions = {
method: "GET",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/users/${promptProject?.tool_id}`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
},
};
setIsShareLoading(true);
getAllUsers();
Expand Down Expand Up @@ -417,9 +402,6 @@ function ListOfTools({ segmentOptions, segmentValue, onSegmentChange }) {
const requestOptions = {
method: "POST",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/${adapter?.tool_id}/share/`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
},
data: {
shared_users: userIds,
shared_to_org: shareWithEveryone || false,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ import { Modal, Tooltip } from "@/components/ui/shims/antd-overlays";
import { Table, Upload } from "@/components/ui/shims/antd-structure";
import { Typography } from "@/components/ui/shims/antd-typography";

import { getCsrfHeaders } from "../../../helpers/csrf";
import { useAxiosPrivate } from "../../../hooks/useAxiosPrivate";
import { useExceptionHandler } from "../../../hooks/useExceptionHandler";
import { useAlertStore } from "../../../store/alert-store";
Expand Down Expand Up @@ -669,7 +670,6 @@ function ManageDocsModal({
method: "DELETE",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/file/${details?.tool_id}`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: body,
Expand Down Expand Up @@ -746,9 +746,7 @@ function ManageDocsModal({
<Upload.Dragger
name="file"
action={`/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/file/${details?.tool_id}`}
headers={{
"X-CSRFToken": sessionDetails.csrfToken,
}}
headers={getCsrfHeaders()}
onChange={handleUploadChange}
disabled={isUploading || !defaultLlmProfile}
showUploadList={false}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -93,7 +93,6 @@ function ManageLlmProfiles() {
method: "PATCH",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/prompt-studio-profile/${details?.tool_id}/`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: body,
Expand Down Expand Up @@ -206,9 +205,6 @@ function ManageLlmProfiles() {
const requestOptions = {
method: "DELETE",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/profile-manager/${profileId}/`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
},
};

axiosPrivate(requestOptions)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -199,9 +199,6 @@ function OutputForDocModal({
const requestOptions = {
method: "GET",
url,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
},
};
setIsLoading(true);
axiosPrivate(requestOptions)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -112,7 +112,6 @@ function PromptsReorder({ isOpen, updateReorderedStatus }) {
method: "POST",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/prompt/reorder/`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: body,
Expand All @@ -130,7 +129,6 @@ function PromptsReorder({ isOpen, updateReorderedStatus }) {
handleDropError,
handleDropSuccess,
previousListOfPrompts,
sessionDetails?.csrfToken,
sessionDetails?.orgId,
updateReorderedStatus,
],
Expand Down
3 changes: 0 additions & 3 deletions frontend/src/components/custom-tools/tool-ide/ToolIde.jsx
Original file line number Diff line number Diff line change
Expand Up @@ -238,7 +238,6 @@ function ToolIde() {
method: "POST",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/export/${details?.tool_id}`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: {
Expand Down Expand Up @@ -302,7 +301,6 @@ function ToolIde() {
method: "POST",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/index-document/${details?.tool_id}`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: body,
Expand All @@ -324,7 +322,6 @@ function ToolIde() {
method: "PATCH",
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/${details?.tool_id}/`,
headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: body,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -142,7 +142,6 @@ function ToolsMain() {
url: `/api/v1/unstract/${sessionDetails?.orgId}/prompt-studio/prompt-studio-prompt/${details?.tool_id}/`,

headers: {
"X-CSRFToken": sessionDetails?.csrfToken,
"Content-Type": "application/json",
},
data: body,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,11 +7,9 @@ function apiDeploymentsService() {
const axiosPrivate = useAxiosPrivate();
const { sessionDetails } = useSessionStore();
const path = `/api/v1/unstract/${sessionDetails.orgId.replaceAll('"', "")}`;
const csrfToken = sessionDetails.csrfToken;

const requestHeaders = {
"Content-Type": "application/json",
"X-CSRFToken": csrfToken,
};

return {
Expand Down
Loading
Loading