(async () => { // 1. Get the Project ID from the URL const projectId = window.location.pathname.split('/')[2]; // 2. Grab the CSRF Token from your browser cookies const cookieValue = document.cookie .split('; ') .find(row => row.startsWith('scratchcsrftoken')) ?.split('=')[1]; if (!cookieValue) { return console.error("Could not find CSRF token. Try logging out and back in."); } // 3. Create the file picker const input = document.createElement("input"); input.type = "file"; input.accept = "image/gif"; input.onchange = async () => { const file = input.files[0]; // Check file size (Scratch usually caps at 512KB - 1MB for thumbnails) if (file.size > 1024 * 1024) { alert("Your GIF is too big! Try a file under 500KB."); return; } const url = `/internalapi/project/thumbnail/${projectId}/set/`; console.log("Sending request with CSRF Token..."); const response = await fetch(url, { method: "POST", body: file, headers: { "X-CSRFToken": cookieValue, "X-Requested-With": "XMLHttpRequest" } }); if (response.ok) { alert("Success! The GIF is uploaded. Refresh the page!"); } else { const errorText = await response.text(); console.error("Server says:", errorText); alert("Upload failed. Status: " + response.status); } }; input.click(); })();