Validate WORLDMONITOR_API_KEY before allowing cloud fallback#218
Merged
Conversation
Restore the WORLDMONITOR_API_KEY check that was removed in e882a00, which left desktop cloud fallback ungated — causing deterministic 401s from the edge gateway for keyless desktop installs. Also disable cloud fallback when the runtime-config module fails to import, since the cloudFallback() path depends on the same module and would throw. https://claude.ai/code/session_014yJsGsxD1sWt6B6PvQXiaA
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
facusturla
pushed a commit
to facusturla/worldmonitor
that referenced
this pull request
Feb 27, 2026
…koala73#218) Restore the WORLDMONITOR_API_KEY check that was removed in 740e351, which left desktop cloud fallback ungated — causing deterministic 401s from the edge gateway for keyless desktop installs. Also disable cloud fallback when the runtime-config module fails to import, since the cloudFallback() path depends on the same module and would throw. https://claude.ai/code/session_014yJsGsxD1sWt6B6PvQXiaA Co-authored-by: Claude <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add validation of the
WORLDMONITOR_API_KEYsecret before allowing cloud fallback in the runtime fetch patch. If the API key is missing or invalid, cloud fallback is now disabled. Additionally, if the secrets module fails to load, cloud fallback is disabled rather than silently allowed.Type of change
Affected areas
/api/*)Details
The runtime fetch patch now:
getSecretStatein addition tosecretsReadyfrom the runtime-config serviceWORLDMONITOR_API_KEYsecret after waiting for secrets to be readyThis ensures that cloud fallback requests are only made when a valid API key is available.
Checklist
api/rss-proxy.jsallowlist (if adding feeds)npm run typecheck)https://claude.ai/code/session_014yJsGsxD1sWt6B6PvQXiaA