feat: honor KEY_PROVIDER_URL scheme and validate at config load - #272
Conversation
|
@claude review |
|
Claude finished @danielpeng1's task —— View job PR Review: Key Provider URL Scheme ValidationTodo List:
Review SummaryThis PR successfully implements URL scheme validation for key provider configurations and stops automatic URL rewriting in the client. The implementation is well-designed and addresses important security concerns around plaintext HTTP usage. ✅ StrengthsSecurity-Focused Design
Clean Client Implementation
Comprehensive Test Coverage
Good Documentation
🔍 Code Quality ObservationsConfiguration Validation (
|
Stop rewriting the key provider URL in the client and validate provider URLs at config load.
KeyProviderClient: use the configured URL scheme; keep existing mTLS agent behavior whenTLS_MODE=mtlsinitConfig: validateKEY_PROVIDER_URLand optionalBACKUP_KMS_URL; addALLOW_PLAINTEXT_KEY_PROVIDERfor local/dev setupsdocker-compose.ymlupdates for the new env varTests
config.test.ts: URL scheme validationkeyProviderClient.test.ts: no scheme downgrade when TLS is disabled on the appTicket: WCN-1927