Pull requests / #956
#956 serve: an API key with spaces around it or outside Latin-1 works, and a refused key is not called a missing one (#725)
closed · @BGonnermann · 0 comments · View on GitHub
Description
For #725 (the web app keeps asking for the API key after one is saved). **What I could and could not reproduce.** On current main (`6f32ec0`) the plain case of the issue works: with `--api-key test-key-123` the key saves under About > Settings and chat answers. So I have not reproduced the reporter's exact case and cannot say which of the causes below they hit. Trying ten key shapes through the web app found three defects that give the reported behaviour. ## The three defects 1. **A key with a space or a line end around it matched no request.** An HTTP header loses those characters (and the server strips the Bearer value, the web app trims its field), but the server kept its own key as given. A key from a config or environment file with CRLF line ends, or a quoted `" key "`, gave every client 401 with the right key. The server now keeps the key without them. A key that is only such characters stops the start, as an empty one does (#213); it never turns the check off. 2. **A key outside Latin-1 never worked.** The web app's `fetch()` throws on such a header value (the pill went to "Server not reachable"), and the server re-encoded the header's bytes before comparing, so a UTF-8 key from curl did not match either. The web app now sends the key as UTF-8, and the server accepts the UTF-8 and the Latin-1 form of the right key. The comparison is still `hmac.compare_digest`. 3. **A refused key was called a missing one.** With a saved key the server refuses, the web app said "API key needed: add it under About > Settings". It now says "API key not accepted" and to check the key. A newly saved key shows the note again if it is refused too. A number as `"api_key"` in the config file (`"api_key": 12345`) is read as text now; before, `.encode()` failed on each request. ## Measured Windows 11, Python 3.14, `--engine mock`, headless Edge driven by Playwright; one server per key, the key typed into About > Settings, the status pill read 3.5 s later. | key | before | after | |---|---|---| | `sk-abc123` | Idle | Idle | | `p@ss w0rd!` | Idle | Idle | | `" padded "` | API key needed | Idle | | `"trail\r"` | API key needed | Idle | | `q"uote\` | Idle | Idle | | `clé-ünï` | Idle | Idle | | `пароль` | Server not reachable | Idle | | `12345` | Idle | Idle | | `true` | Idle | Idle | | 200 x `a` | Idle | Idle | With a wrong key saved: pill "API key not accepted" (before: "API key needed"); with the right key after it: Idle. `python -m unittest serve.test_server`: 143 tests, OK (4 new, `ApiKeyForms`). Not measured: Firefox and Safari, and a blank `"api_key"` in a config file on a real start (only `--api-key " "` was run; the config path goes through the same `api_key_of`, which the unit test covers). 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Related on strata.com
Editorial links to help you install, pick models, or read release notes — not part of the upstream thread.