INNER CODE UNIT · TypeScript
isLoopbackHost
caura-ai/caura · clients/typescript/src/index.ts:27
function isLoopbackHost(hostname: string): boolean {
const host = hostname.toLowerCase().replace(/^\[(.*)\]$/, "$1");
return (
host === "localhost" ||
host.endsWith(".localhost") ||
host === "::1" ||
/^127\.\d{1,3}\.\d{1,3}\.\d{1,3}$/.test(host)
);
}
function envAllowsInsecureHttp(): boolean {
const env = (globalThis as { process?: { env?: Record<string, string | undefined> } }).process?.env;
return ["true", "1"].includes(env?.CAURA_ALLOW_INSECURE_HTTP ?? "");
}
/**
* Refuse to send the API key in cleartext to another machine (L-66): https, or
* plain http to a loopback host, or an explicit opt-in. The same rule as the