Commit 553ef3e
fix(installer): strip ANTHROPIC_API_KEY on legacy fallback path
Addresses Greptile P1: the legacy fallback path (no refresh token or
INSTALLER_DISABLE_PROXY=1) still leaked the user's personal
ANTHROPIC_API_KEY to the WorkOS gateway as an x-api-key header
alongside the WorkOS access token. Every other non-direct path already
deletes it; this brings the legacy branch in line.
Also clarifies the skip-auth/local log messages to reflect that a
placeholder bearer is now forwarded to the gateway (the SDK's local
auth-source check would otherwise fail with 'Not logged in').
Co-Authored-By: nick.nisi@workos.com <nick.nisi@workos.com>1 parent c270be8 commit 553ef3e
2 files changed
Lines changed: 27 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
471 | 471 | | |
472 | 472 | | |
473 | 473 | | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
| 487 | + | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
474 | 491 | | |
475 | 492 | | |
476 | 493 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
455 | 455 | | |
456 | 456 | | |
457 | 457 | | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
458 | 462 | | |
459 | 463 | | |
460 | 464 | | |
461 | 465 | | |
462 | 466 | | |
463 | | - | |
464 | | - | |
465 | | - | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
466 | 471 | | |
467 | 472 | | |
468 | 473 | | |
469 | 474 | | |
470 | | - | |
| 475 | + | |
471 | 476 | | |
472 | 477 | | |
473 | 478 | | |
474 | 479 | | |
475 | 480 | | |
476 | 481 | | |
477 | | - | |
| 482 | + | |
478 | 483 | | |
479 | 484 | | |
480 | 485 | | |
| |||
0 commit comments