Skip to content

Commit cf6e2a7

Browse files
committed
fix: add missing postRawRequestFull to base_actions.js
profile/actions.js imports postRawRequestFull for the new enableTwoFactor and regenerateRecoveryCodes flows, but it was never exported, causing a runtime TypeError on both actions. Falling back to postRawRequest is unsafe here since it copies params into the URL query string, which would leak current_password into access logs.
1 parent e0620ef commit cf6e2a7

1 file changed

Lines changed: 24 additions & 0 deletions

File tree

‎resources/js/base_actions.js‎

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -92,6 +92,30 @@ export const postRawRequest = (endpoint) => (params, headers = {}) => {
9292
})
9393
}
9494

95+
export const postRawRequestFull = (endpoint) => (params, headers = {}) => {
96+
let url = URI(endpoint);
97+
98+
let key = url.toString();
99+
100+
cancel(key);
101+
102+
let req = http.post(url.toString());
103+
104+
schedule(key, req);
105+
106+
return req.set(headers).send(params).timeout({
107+
response: 60000,
108+
deadline: 60000,
109+
}).then((res) => {
110+
let json = res.body;
111+
end(key);
112+
return Promise.resolve({response: json});
113+
}).catch((error) => {
114+
end(key);
115+
return Promise.reject(error);
116+
})
117+
}
118+
95119
export const putRawRequest = (endpoint) => (payload = null, params={}, headers = {}) => {
96120
let url = URI(endpoint);
97121

0 commit comments

Comments
 (0)