/
githubmirror
/
angular
Обзор
Документация
Войти
/
githubmirror
/
angular
Код
Запросы
0
Пакеты
0
Релизы
0
Аналитика
Безопасность
main
packages/common/http/src/module.ts
121 строка
4 KB
Alan Agius
refactor(http): deprecate jsonp support
05 июн 2026, 01:28
05 июн 2026, 01:28
af04e26
Код
Авторство
О чём код?
/** * @license * Copyright Google LLC All Rights Reserved. * * Use of this source code is governed by an MIT-style license that can be * found in the LICENSE file at https://angular.dev/license */ import {ModuleWithProviders, NgModule} from '@angular/core'; import {HTTP_INTERCEPTORS} from './interceptor'; import { provideHttpClient, withInterceptorsFromDi, withJsonpSupport, withNoXsrfProtection, withXhr, withXsrfConfiguration, } from './provider'; import { HttpXsrfCookieExtractor, HttpXsrfInterceptor, HttpXsrfTokenExtractor, XSRF_DEFAULT_COOKIE_NAME, XSRF_DEFAULT_HEADER_NAME, XSRF_ENABLED, } from './xsrf'; /** * Configures XSRF protection support for outgoing requests. * * For a server that supports a cookie-based XSRF protection system, * use directly to configure XSRF protection with the correct * cookie and header names. * * If no names are supplied, the default cookie name is `XSRF-TOKEN` * and the default header name is `X-XSRF-TOKEN`. * * @publicApi * @deprecated Use withXsrfConfiguration({cookieName: 'XSRF-TOKEN', headerName: 'X-XSRF-TOKEN'}) as * providers instead or `withNoXsrfProtection` if you want to disabled XSRF protection. */ @NgModule({ providers: [ HttpXsrfInterceptor, {provide: HTTP_INTERCEPTORS, useExisting: HttpXsrfInterceptor, multi: true}, {provide: HttpXsrfTokenExtractor, useClass: HttpXsrfCookieExtractor}, withXsrfConfiguration({ cookieName: XSRF_DEFAULT_COOKIE_NAME, headerName: XSRF_DEFAULT_HEADER_NAME, }).ɵproviders, {provide: XSRF_ENABLED, useValue: true}, ], }) export class HttpClientXsrfModule { /** * Disable the default XSRF protection. */ static disable(): ModuleWithProviders<HttpClientXsrfModule> { return { ngModule: HttpClientXsrfModule, providers: [withNoXsrfProtection().ɵproviders], }; } /** * Configure XSRF protection. * @param options An object that can specify either or both * cookie name or header name. * - Cookie name default is `XSRF-TOKEN`. * - Header name default is `X-XSRF-TOKEN`. * */ static withOptions( options: { cookieName?: string; headerName?: string; } = {}, ): ModuleWithProviders<HttpClientXsrfModule> { return { ngModule: HttpClientXsrfModule, providers: withXsrfConfiguration(options).ɵproviders, }; } } /** * Configures the dependency injector for `HttpClient` * with supporting services for XSRF. Automatically imported by `HttpClientModule`. * * You can add interceptors to the chain behind `HttpClient` by binding them to the * multiprovider for built-in DI token `HTTP_INTERCEPTORS`. * * When importing the `HttpClientModule`, the `HttpBackend` is set to using the `HttpXhrBackend`. * If you want to use the `FetchBackend`, use `provideHttpClient` instead. * * @publicApi * @deprecated use `provideHttpClient(withInterceptorsFromDi())` as providers instead */ @NgModule({ /** * Configures the dependency injector where it is imported * with supporting services for HTTP communications. */ providers: [provideHttpClient(withInterceptorsFromDi(), withXhr())], }) export class HttpClientModule {} /** * Configures the dependency injector for `HttpClient` * with supporting services for JSONP. * Without this module, Jsonp requests reach the backend * with method JSONP, where they are rejected. * * @publicApi * @deprecated 22.1 JSONP is deprecated as it can cause XSS vulnerabilities. Intent to remove in future versions of Angular. */ @NgModule({ providers: [withJsonpSupport().ɵproviders], }) export class HttpClientJsonpModule {}