diff --git a/apps/internal-ui/src/api/client.ts b/apps/internal-ui/src/api/client.ts index 534f19c..6fa2a39 100644 --- a/apps/internal-ui/src/api/client.ts +++ b/apps/internal-ui/src/api/client.ts @@ -1,6 +1,10 @@ const configuredApiBase = (import.meta.env.VITE_API_BASE_URL ?? "").replace(/\/+$/, ""); let activeOrganizationPublicId: string | null = null; +// Имя CSRF-cookie должно совпадать с backend CSRF_COOKIE_NAME (settings_app): +// production (SESSION_COOKIE_SECURE) → "__Host-custocrm-app-csrf". +const CSRF_COOKIE_NAME = "__Host-custocrm-app-csrf"; + const tenantNamespaces = [ "access-profiles", "ai", @@ -62,7 +66,7 @@ export async function api(path: string, init: RequestInit = {}): Promise { headers.set("Accept", "application/json"); if (method !== "GET") { headers.set("Content-Type", "application/json"); - headers.set("X-CSRFToken", getCookie("csrftoken")); + headers.set("X-CSRFToken", getCookie(CSRF_COOKIE_NAME)); } const response = await fetch(resolveApiUrl(path), { ...init, @@ -79,7 +83,7 @@ export async function api(path: string, init: RequestInit = {}): Promise { // Multipart-загрузка (вложения знаний): Content-Type выставляет браузер (boundary). export async function apiUpload(path: string, form: FormData): Promise { - const headers = new Headers({ Accept: "application/json", "X-CSRFToken": getCookie("csrftoken") }); + const headers = new Headers({ Accept: "application/json", "X-CSRFToken": getCookie(CSRF_COOKIE_NAME) }); const response = await fetch(resolveApiUrl(path), { method: "POST", body: form, credentials: "include", headers }); if (!response.ok) { const payload = await response.json().catch(() => ({ detail: "Ошибка запроса" }));