Repository navigation
fix: send auth header as api-access-token - #43
Conversation
Reverse proxies that drop headers containing underscores (Caddy 2.6.4+ by default, nginx with underscores_in_headers off) stripped the api_access_token header, so every request to a self-hosted instance behind them failed with 401. Rack servers map both spellings to HTTP_API_ACCESS_TOKEN, which is what Chatwoot reads, so the hyphenated form needs no server-side change. Closes #41
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Merging this branch will not change overall coverage
Coverage by fileChanged files (no unit tests)
Please note that the "Total", "Covered", and "Missed" counts above refer to code statements instead of lines of code. The value in brackets refers to the test coverage of that file in the old version of the code. Changed unit test files
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 479f61e702
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| } | ||
|
|
||
| req.Header.Set("api_access_token", c.APIKey) | ||
| req.Header.Set("api-access-token", c.APIKey) |
There was a problem hiding this comment.
Honor underscore-form token overrides in raw API calls
When an account-scoped raw call supplies Chatwoot's documented -H 'api_access_token: ...' header, RequestRaw deletes only that underscore-form key (internal/sdk/client.go:254-258), not the new Api-Access-Token, because Go treats the two names as distinct. Both values are therefore sent, and Rack/Puma's collision handling can prefer the configured hyphenated token instead of the caller's override. This regresses the previous override behavior for the spelling still advertised by the pinned Swagger; normalize this alias or delete both forms before applying custom headers.
Useful? React with 👍 / 👎.
Closes #41
Problem
The CLI sent its token as
api_access_token. Reverse proxies that drop headers containing underscores — Caddy 2.6.4+ by default, nginx with the defaultunderscores_in_headers off— strip it, so every call to a self-hosted instance behind them fails with401.Fix
Send
api-access-tokeninstead. Server side this is equivalent:request.headers[:HTTP_API_ACCESS_TOKEN](access_token_auth_helper.rb).api-access-token→HTTP_API_ACCESS_TOKEN.No server change needed; direct-to-Rails setups are unaffected.
Changes
internal/sdk/client.go: header name inrequestandrawRequestinternal/sdk/CLAUDE.mdandCHANGELOG.mdupdated