I am able to log into a site using PHP & CURL, collecting the token and using that. Going to the page, the form contains something like this:
<input type="hidden" name="authenticity_token" value="xxxxxxxxxxxxx" />
Then there's also a meta tag like this:
<meta name="csrf-token" content="xxxxxxxxxxxxx" />
I'll get the token from the meta tag and use that to log in.
However, on one site I'm trying to access the form input looks like this:
<input type="hidden" name="csrfmiddlewaretoken" value="yyyyyyyyyy">
And I can't find the meta tag to take the token from. (If I try taking it from the input field it doesn't work.)
There is, however, this line
<script src="https://cdnjs.cloudflare.com/ajax/libs/htmx/1.6.0/htmx.min.js" integrity="xyxyxyxyxyxyxyxyxyx" crossorigin="anonymous" referrerpolicy="no-referrer"></script>
Is the token generated from here? And if so, how can I de-obfuscate it?