Skip to content
12 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Merge main into Artifacts Phase 21/**
2 * Whether a request came from another site: its `Origin` names an origin
3 * other than the site's own. Form posts from g1t's pages carry the site's
4 * origin; a request without the header (not from a browser's form) is not
5 * cross-site. lib/session.server.ts's `assertSameOrigin` refuses these on
6 * every action, for a session cookie and an access token alike
7 * (lib/website-token.ts).
8 */
9export function crossOrigin(request: Request): boolean {
10 const origin = request.headers.get("origin");
11 return Boolean(origin && origin !== new URL(request.url).origin);
12}

This file's history is long; its oldest lines are credited to the oldest commit read.