Avoid sending API key for remote resources

Thanks to Abdo for the report

(cherry picked from commit fbb4cf6124)
This commit is contained in:
Damien Elmes 2025-04-16 22:11:11 +10:00
parent 097f9bd138
commit 3f9f3b248e

View file

@ -69,7 +69,7 @@ class AuthInterceptor(QWebEngineUrlRequestInterceptor):
def interceptRequest(self, info):
from aqt.mediasrv import _APIKEY
if self._api_enabled:
if self._api_enabled and info.requestUrl().host() == "127.0.0.1":
info.setHttpHeader(b"Authorization", f"Bearer {_APIKEY}".encode("utf-8"))