Bind the API key to its endpoint's origin; don't follow redirects #3

Merged
florian merged 1 commit from bind-key-to-endpoint into main 2026-10-05 13:01:07 +02:00
Owner

The saved key was independent of the endpoint, so switching vendor,
mistyping a host or pointing at someone else's server sent the old key
there on the next transcription.

The key is now stored with the origin (scheme, host, port) it was saved
for. Saving a different origin removes it unless a new key is entered,
and Settings warns before saving. apiKeyFor() refuses to return the key
for any other origin. Keys saved by 0.2.x are bound to the endpoint
they're currently used with.

Transcription requests no longer follow redirects: a cross-host
redirect would forward ElevenLabs' xi-api-key header (Android's HTTP
stack only strips Authorization). A redirect now fails with a message
naming the target.

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com

The saved key was independent of the endpoint, so switching vendor, mistyping a host or pointing at someone else's server sent the old key there on the next transcription. The key is now stored with the origin (scheme, host, port) it was saved for. Saving a different origin removes it unless a new key is entered, and Settings warns before saving. apiKeyFor() refuses to return the key for any other origin. Keys saved by 0.2.x are bound to the endpoint they're currently used with. Transcription requests no longer follow redirects: a cross-host redirect would forward ElevenLabs' xi-api-key header (Android's HTTP stack only strips Authorization). A redirect now fails with a message naming the target. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The saved key was independent of the endpoint, so switching vendor,
mistyping a host or pointing at someone else's server sent the old key
there on the next transcription.

The key is now stored with the origin (scheme, host, port) it was saved
for. Saving a different origin removes it unless a new key is entered,
and Settings warns before saving. apiKeyFor() refuses to return the key
for any other origin. Keys saved by 0.2.x are bound to the endpoint
they're currently used with.

Transcription requests no longer follow redirects: a cross-host
redirect would forward ElevenLabs' xi-api-key header (Android's HTTP
stack only strips Authorization). A redirect now fails with a message
naming the target.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
florian deleted branch bind-key-to-endpoint 2026-10-05 13:01:07 +02:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
florian/peggypad!3
No description provided.