Avoid sending API key for remote resources

Thanks to Abdo for the report
This commit is contained in:
Damien Elmes 2025-04-16 22:11:11 +10:00
parent b02111bb2c
commit fbb4cf6124

View file

@ -69,7 +69,7 @@ class AuthInterceptor(QWebEngineUrlRequestInterceptor):
def interceptRequest(self, info):
from aqt.mediasrv import _APIKEY
if self._api_enabled:
if self._api_enabled and info.requestUrl().host() == "127.0.0.1":
info.setHttpHeader(b"Authorization", f"Bearer {_APIKEY}".encode("utf-8"))