Skip to content
12 linesCodeBlameRaw
1/**
2 * Whether a request came from another site: its `Origin` names an origin
3 * other than the site's own. Form posts from g1t's pages carry the site's
4 * origin; a request without the header (not from a browser's form) is not
5 * cross-site. lib/session.server.ts's `assertSameOrigin` refuses these on
6 * every action, for a session cookie and an access token alike
7 * (lib/website-token.ts).
8 */
9export function crossOrigin(request: Request): boolean {
10 const origin = request.headers.get("origin");
11 return Boolean(origin && origin !== new URL(request.url).origin);
12}