API key authentication + CORS + security headers #12

Open
opened 2026-08-03 16:55:36 -07:00 by kalmiya · 0 comments
Owner

Kanban ticket: t_5b38ef4d
Board: hermes-anthropic-api


Task t_5b38ef4d: API key authentication + CORS + security headers
status: ready
assignee: -
workspace: scratch
max-retries: 2 (default)
created: 2026-08-03 16:53 by kalmiya

Body:
Authentication matches Anthropic's convention.

  • Anthropic clients send Authorization: Bearer <key> (NOT Basic auth).
  • Compare constant-time against the key resolved from ANTHROPIC_API_KEY env var (or whatever gateway.platforms.anthropic_api.extra.api_key_env points to).
  • On mismatch: 401 with authentication_error envelope.
  • On missing header: 401 with authentication_error envelope.
  • CORS: configurable allowlist via cors_origins extra (default []).
  • Security headers: reuse the same set api_server emits (X-Content-Type-Options, Referrer-Policy, etc.).

Auth middleware order (matters): CORS preflight → security headers → body-limit → auth → handler.

Events (1):
[2026-08-03 16:53] created {'assignee': None, 'status': 'ready', 'parents': [], 'tenant': None, 'workspace_kind': 'scratch', 'workspace_path': None, 'branch_name': None, 'project_id': None, 'skills': None, 'goal_mode': None, 'model_override': None, 'provider_override': None}

**Kanban ticket:** `t_5b38ef4d` **Board:** `hermes-anthropic-api` --- Task t_5b38ef4d: API key authentication + CORS + security headers status: ready assignee: - workspace: scratch max-retries: 2 (default) created: 2026-08-03 16:53 by kalmiya Body: Authentication matches Anthropic's convention. - Anthropic clients send `Authorization: Bearer <key>` (NOT Basic auth). - Compare constant-time against the key resolved from `ANTHROPIC_API_KEY` env var (or whatever `gateway.platforms.anthropic_api.extra.api_key_env` points to). - On mismatch: 401 with `authentication_error` envelope. - On missing header: 401 with `authentication_error` envelope. - CORS: configurable allowlist via `cors_origins` extra (default `[]`). - Security headers: reuse the same set api_server emits (`X-Content-Type-Options`, `Referrer-Policy`, etc.). Auth middleware order (matters): CORS preflight → security headers → body-limit → auth → handler. Events (1): [2026-08-03 16:53] created {'assignee': None, 'status': 'ready', 'parents': [], 'tenant': None, 'workspace_kind': 'scratch', 'workspace_path': None, 'branch_name': None, 'project_id': None, 'skills': None, 'goal_mode': None, 'model_override': None, 'provider_override': None}
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kalmiya/hermes-anthropic-api#12
No description provided.