Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Automation driving a browser can use g1t.sh as a person by sending their access token as Authorization: Bearer on every request, once the token has Use the website as you ticked on its form: no cookie or session is made, the token is checked on each request and refused at once when deleted, expired or revoked, never read from a query string or cookie, counted at the API's limit per token, and never served or kept as a public page, while tokens, two-factor authentication, emails, keys, the account, applications, device and application sign-ins, workspace deletion and transfer, and payment pages answer This needs you to sign in, a token without the permission is signed out with a 401 for data requests and form posts, and form posts from other sites are refused for cookies and tokens alike. | 1 | /** |
| 2 | * Whether a request came from another site: its `Origin` names an origin | |
| 3 | * other than the site's own. Form posts from g1t's pages carry the site's | |
| 4 | * origin; a request without the header (not from a browser's form) is not | |
| 5 | * cross-site. lib/session.server.ts's `assertSameOrigin` refuses these on | |
| 6 | * every action, for a session cookie and an access token alike | |
| 7 | * (lib/website-token.ts). | |
| 8 | */ | |
| 9 | export function crossOrigin(request: Request): boolean { | |
| 10 | const origin = request.headers.get("origin"); | |
| 11 | return Boolean(origin && origin !== new URL(request.url).origin); | |
| 12 | } |