Skip to content

Trust canonical host alongside API host - #289

Merged
williammartin merged 1 commit into
trunkfrom
williammartin-relax-api-host-auth
Sep 3, 2026
Merged

Trust canonical host alongside API host#289
williammartin merged 1 commit into
trunkfrom
williammartin-relax-api-host-auth

Conversation

@williammartin

@williammartin williammartin commented Sep 2, 2026

Copy link
Copy Markdown
Member

Description

api_host is a routing feature, not a security boundary that should prevent the canonical host from receiving its token.

Authorship and follow-up

Who wrote this:

  • A human wrote it.
  • An agent wrote it under close human direction.
  • An agent wrote it independently, and no human has guided the implementation beyond the initial prompt.

Who answers review comments:

  • @williammartin will read and reply directly. Name the account.
  • An agent will draft replies and @username will read them before they are posted.
  • Nobody has explicitly committed to replying.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@williammartin
williammartin deleted the williammartin-relax-api-host-auth branch September 2, 2026 15:53
@williammartin
williammartin restored the williammartin-relax-api-host-auth branch September 2, 2026 15:54
@williammartin williammartin reopened this Sep 2, 2026
@williammartin
williammartin marked this pull request as ready for review September 3, 2026 10:53
@williammartin
williammartin requested a review from a team as a code owner September 3, 2026 10:53
@williammartin
williammartin requested review from tidy-dev and removed request for a team September 3, 2026 10:53

@babakks babakks left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@williammartin
williammartin merged commit c9808f2 into trunk Sep 3, 2026
21 checks passed
@williammartin
williammartin deleted the williammartin-relax-api-host-auth branch September 3, 2026 11:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants