INNER CODE UNIT · TypeScript
assertKeyTransportAllowed
caura-ai/caura · clients/typescript/src/index.ts:47
function assertKeyTransportAllowed(baseUrl: string, allowInsecureHttp: boolean | undefined): void {
const expected = "baseUrl must start with https:// (or http:// for a loopback host)";
let url: URL;
try {
url = new URL(baseUrl);
} catch {
throw new Error(`${expected}; got an invalid URL`);
}
if (url.protocol !== "http:" && url.protocol !== "https:") {
throw new Error(`${expected}; got ${url.protocol}`);
}
if (url.protocol === "https:" || isLoopbackHost(url.hostname)) return;
if (allowInsecureHttp ?? envAllowsInsecureHttp()) return;
throw new Error(
`Refusing to send the API key to ${url.host}: baseUrl uses plain HTTP to a non-loopback host, ` +
`so the key would cross the network in cleartext. Use https://, or pass allowInsecureHttp: true ` +
`(or set CAURA_ALLOW_INSECURE_HTTP=true) to accept the risk, e.g. on a trusted private network.`,
);