1
0
mirror of synced 2025-12-25 02:17:36 -05:00

Inline CSRF token in HTML (#17748)

* Inline CSRF token

* Fix tests
This commit is contained in:
Kevin Heis
2021-02-09 14:08:24 -08:00
committed by GitHub
parent 6d20e43444
commit 1918d2ea14
8 changed files with 33 additions and 68 deletions

View File

@@ -1,20 +1,19 @@
<head>
{% comment %} For human readers {% endcomment %}
<meta charset="utf-8" />
<title>{% if error == '404' %}{% data ui.errors.oops %}{% elsif currentVersion == 'homepage' %}GitHub Documentation{% elsif page.fullTitle %}{{ page.fullTitle }}{% else %}GitHub Documentation{% endif %}</title>
<meta name="viewport" content="width=device-width, initial-scale=1">{% if page.hidden %}
<meta name="robots" content="noindex" />{% endif %}
<meta name="google-site-verification" content="OgdQc0GZfjDI52wDv1bkMT-SLpBUo_h5nn9mI9L22xQ" />
<meta name="google-site-verification" content="c1kuD-K2HIVF635lypcsWPoD4kilo5-jA_wBFyT4uMY" />
<!-- localized data needed by client-side JS -->
<meta name="site.data.ui.search.placeholder" content="{% data ui.search.placeholder %}">
<!-- end localized data -->
<meta name="viewport" content="width=device-width, initial-scale=1">
<link rel="alternate icon" type="image/png" href="/assets/images/site/favicon.png">
<link rel="icon" type="image/svg+xml" href="/assets/images/site/favicon.svg">
<link rel="stylesheet" href="{{ builtAssets.main.css }}">
{% comment %} For Google and Bots {% endcomment %}
{% if page.intro %}
<meta name="description" content="{{ page.introPlainText }}">
{% endif %}
<!-- hreflangs -->
{% if page.hidden %}
<meta name="robots" content="noindex" />
{% endif %}
{% for languageVariant in page.languageVariants %}
<link
rel="alternate"
@@ -22,8 +21,10 @@
href="https://docs.github.com{{ languageVariant.href }}"
/>
{% endfor %}
<meta name="google-site-verification" content="OgdQc0GZfjDI52wDv1bkMT-SLpBUo_h5nn9mI9L22xQ" />
<meta name="google-site-verification" content="c1kuD-K2HIVF635lypcsWPoD4kilo5-jA_wBFyT4uMY" />
<link rel="stylesheet" href="{{ builtAssets.main.css }}">
<link rel="alternate icon" type="image/png" href="/assets/images/site/favicon.png">
<link rel="icon" type="image/svg+xml" href="/assets/images/site/favicon.svg">
{% comment %} For our JS {% endcomment %}
<meta name="csrf-token" content="$CSRFTOKEN$">
<meta name="site.data.ui.search.placeholder" content="{% data ui.search.placeholder %}">
</head>