Pull requests / #956

#956 serve: an API key with spaces around it or outside Latin-1 works, and a refused key is not called a missing one (#725)

closed · @BGonnermann · 0 Kommentare · Auf GitHub

Server & APIWindows

Beschreibung

For #725 (the web app keeps asking for the API key after one is saved).

**What I could and could not reproduce.** On current main (`6f32ec0`) the plain case of the issue works: with `--api-key test-key-123` the key saves under About > Settings and chat answers. So I have not reproduced the reporter's exact case and cannot say which of the causes below they hit. Trying ten key shapes through the web app found three defects that give the reported behaviour.

## The three defects

1. **A key with a space or a line end around it matched no request.** An HTTP header loses those characters (and the server strips the Bearer value, the web app trims its field), but the server kept its own key as given. A key from a config or environment file with CRLF line ends, or a quoted `" key "`, gave every client 401 with the right key. The server now keeps the key without them. A key that is only such characters stops the start, as an empty one does (#213); it never turns the check off.
2. **A key outside Latin-1 never worked.** The web app's `fetch()` throws on such a header value (the pill went to "Server not reachable"), and the server re-encoded the header's bytes before comparing, so a UTF-8 key from curl did not match either. The web app now sends the key as UTF-8, and the server accepts the UTF-8 and the Latin-1 form of the right key. The comparison is still `hmac.compare_digest`.
3. **A refused key was called a missing one.** With a saved key the server refuses, the web app said "API key needed: add it under About > Settings". It now says "API key not accepted" and to check the key. A newly saved key shows the note again if it is refused too.

A number as `"api_key"` in the config file (`"api_key": 12345`) is read as text now; before, `.encode()` failed on each request.

## Measured

Windows 11, Python 3.14, `--engine mock`, headless Edge driven by Playwright; one server per key, the key typed into About > Settings, the status pill read 3.5 s later.

| key | before | after |
|---|---|---|
| `sk-abc123` | Idle | Idle |
| `p@ss w0rd!` | Idle | Idle |
| `" padded "` | API key needed | Idle |
| `"trail\r"` | API key needed | Idle |
| `q"uote\` | Idle | Idle |
| `clé-ünï` | Idle | Idle |
| `пароль` | Server not reachable | Idle |
| `12345` | Idle | Idle |
| `true` | Idle | Idle |
| 200 x `a` | Idle | Idle |

With a wrong key saved: pill "API key not accepted" (before: "API key needed"); with the right key after it: Idle.

`python -m unittest serve.test_server`: 143 tests, OK (4 new, `ApiKeyForms`).

Not measured: Firefox and Safari, and a blank `"api_key"` in a config file on a real start (only `--api-key " "` was run; the config path goes through the same `api_key_of`, which the unit test covers).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Mehr auf der Site

Links zu Install, Modellen, Releases.