security(server/client): pass WebSocket API key via X-Api-Key header instead of URL query string - #1174
Closed
amir-rezaei wants to merge 1 commit into
Closed
Conversation
…instead of URL query string
Owner
|
Thanks for the contribution, but CI is failing on this PR (Type Check), and no fix has been pushed. Closing to keep the review queue actionable. Please feel free to reopen once:
A PR that fails its own package's test suite can't be reviewed on its merits, so please verify locally before opening. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This PR resolves issue #1152 by updating the server and client to transport the WebSocket API key via the
X-Api-KeyHTTP header instead of logging credentials in the URL query string.Details
/ws?token=sk-xxx, causing server logs (e.g. uvicorn access logs) and reverse proxies to record secret API keys verbatim in cleartext.taskdog-server): Accepts the API key from theX-Api-Keyheader while keeping the query parametertokenas a fallback for backwards compatibility.taskdog-client): Sends the API key viaextra_headersusing theX-Api-Keyheader during the WebSocket handshake.