INNER CODE UNIT · TypeScript
envAllowsInsecureHttp
caura-ai/caura · clients/typescript/src/index.ts:37
function envAllowsInsecureHttp(): boolean {
const env = (globalThis as { process?: { env?: Record<string, string | undefined> } }).process?.env;
return ["true", "1"].includes(env?.CAURA_ALLOW_INSECURE_HTTP ?? "");
}
/**
* Refuse to send the API key in cleartext to another machine (L-66): https, or
* plain http to a loopback host, or an explicit opt-in. The same rule as the
* OpenClaw plugin's `keyTransportPolicy`.
*/
function assertKeyTransportAllowed(baseUrl: string, allowInsecureHttp: boolean | undefined): void {
const expected = "baseUrl must start with https:// (or http:// for a loopback host)";
let url: URL;
try {
url = new URL(baseUrl);
} catch {
throw new Error(`${expected}; got an invalid URL`);
}