INNER CODE UNIT · TypeScript

assertKeyTransportAllowed

caura-ai/caura · clients/typescript/src/index.ts:47

function assertKeyTransportAllowed(baseUrl: string, allowInsecureHttp: boolean | undefined): void {
  const expected = "baseUrl must start with https:// (or http:// for a loopback host)";
  let url: URL;
  try {
    url = new URL(baseUrl);
  } catch {
    throw new Error(`${expected}; got an invalid URL`);
  }
  if (url.protocol !== "http:" && url.protocol !== "https:") {
    throw new Error(`${expected}; got ${url.protocol}`);
  }
  if (url.protocol === "https:" || isLoopbackHost(url.hostname)) return;
  if (allowInsecureHttp ?? envAllowsInsecureHttp()) return;
  throw new Error(
    `Refusing to send the API key to ${url.host}: baseUrl uses plain HTTP to a non-loopback host, ` +
      `so the key would cross the network in cleartext. Use https://, or pass allowInsecureHttp: true ` +
      `(or set CAURA_ALLOW_INSECURE_HTTP=true) to accept the risk, e.g. on a trusted private network.`,
  );

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…