INNER CODE UNIT · TypeScript

envAllowsInsecureHttp

caura-ai/caura · clients/typescript/src/index.ts:37

function envAllowsInsecureHttp(): boolean {
  const env = (globalThis as { process?: { env?: Record<string, string | undefined> } }).process?.env;
  return ["true", "1"].includes(env?.CAURA_ALLOW_INSECURE_HTTP ?? "");
}

/**
 * Refuse to send the API key in cleartext to another machine (L-66): https, or
 * plain http to a loopback host, or an explicit opt-in. The same rule as the
 * OpenClaw plugin's `keyTransportPolicy`.
 */
function assertKeyTransportAllowed(baseUrl: string, allowInsecureHttp: boolean | undefined): void {
  const expected = "baseUrl must start with https:// (or http:// for a loopback host)";
  let url: URL;
  try {
    url = new URL(baseUrl);
  } catch {
    throw new Error(`${expected}; got an invalid URL`);
  }

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…