INNER CODE UNIT · TypeScript

isLoopbackHost

caura-ai/caura · clients/typescript/src/index.ts:27

function isLoopbackHost(hostname: string): boolean {
  const host = hostname.toLowerCase().replace(/^\[(.*)\]$/, "$1");
  return (
    host === "localhost" ||
    host.endsWith(".localhost") ||
    host === "::1" ||
    /^127\.\d{1,3}\.\d{1,3}\.\d{1,3}$/.test(host)
  );
}

function envAllowsInsecureHttp(): boolean {
  const env = (globalThis as { process?: { env?: Record<string, string | undefined> } }).process?.env;
  return ["true", "1"].includes(env?.CAURA_ALLOW_INSECURE_HTTP ?? "");
}

/**
 * Refuse to send the API key in cleartext to another machine (L-66): https, or
 * plain http to a loopback host, or an explicit opt-in. The same rule as the

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…