Skip to content

fix(deps): send the API key via the Backlog-API-Key header - #168

Merged
lollipop-onl merged 1 commit into
mainfrom
lollipop-onl/feat-api-key-header
Sep 28, 2026
Merged

lollipop-onl merged 1 commit into
mainfrom
lollipop-onl/feat-api-key-header

Conversation

@lollipop-onl

Copy link
Copy Markdown
Collaborator

Summary

The Backlog API now accepts the API key in the Backlog-API-Key request header. This bumps backlog-js from ^0.19.1 to ^0.20.1, which sends the key only in that header instead of appending ?apiKey= to every request URL.

Why

A key in the query string ends up in proxy and server access logs and anywhere else request URLs are recorded. Every request bee makes goes through backlog-js (getClient(), auth login, auth status, bee api), so the dependency bump alone moves all commands to the header.

Notes

  • The other changes in backlog-js 0.20.x are additive (contentType on file responses, stricter Content-Disposition parsing, Document comment types).
  • 0.20.x rejects an apiKey containing control characters (including CR/LF), since header values cannot carry them.
  • The apiKey query masking in http-logger.ts is kept: it still hides a key passed explicitly as a query parameter via bee api.

Test plan

  • Stubbed fetch and confirmed the request URL has no apiKey and the headers contain Backlog-API-Key
  • vp check
  • vp test (118 files, 792 tests)

🤖 Generated with Claude Code

The Backlog API now accepts the API key in the `Backlog-API-Key` request
header. backlog-js 0.19.x still appended it as an `apiKey` query parameter,
which leaks the key into proxy and server access logs, browser-style
history, and anything else that records request URLs.

backlog-js 0.20.x sends the key only in the header, and every request bee
makes goes through backlog-js, so bumping the catalog version is enough to
move all commands off the query-string transport.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@lollipop-onl lollipop-onl added the bug Something isn't working label Sep 28, 2026
@lollipop-onl lollipop-onl self-assigned this Sep 28, 2026
@github-actions

Copy link
Copy Markdown

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 92.73% 1940 / 2092
🔵 Statements 92.94% 2029 / 2183
🔵 Functions 92.85% 455 / 490
🔵 Branches 80.57% 842 / 1045
File CoverageNo changed files found.
Generated in workflow #534 for commit e1ad591 by the Vitest Coverage Report Action

@lollipop-onl
lollipop-onl merged commit 707ab80 into main Sep 28, 2026
10 checks passed
@lollipop-onl
lollipop-onl deleted the lollipop-onl/feat-api-key-header branch September 28, 2026 17:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant