Bind the API key to its endpoint's origin; don't follow redirects #3
Loading…
Reference in a new issue
No description provided.
Delete branch "bind-key-to-endpoint"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The saved key was independent of the endpoint, so switching vendor,
mistyping a host or pointing at someone else's server sent the old key
there on the next transcription.
The key is now stored with the origin (scheme, host, port) it was saved
for. Saving a different origin removes it unless a new key is entered,
and Settings warns before saving. apiKeyFor() refuses to return the key
for any other origin. Keys saved by 0.2.x are bound to the endpoint
they're currently used with.
Transcription requests no longer follow redirects: a cross-host
redirect would forward ElevenLabs' xi-api-key header (Android's HTTP
stack only strips Authorization). A redirect now fails with a message
naming the target.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com