Skip to content

Commit 8fa0f15

Browse files
committed
Require explicit trust for custom API origins
1 parent a05aa95 commit 8fa0f15

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

‎skills/beatapi-video/SKILL.md‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,9 @@ server-side code. The Skills-only distribution requires Node.js 20.19+ or
4242
otherwise follow its exact next step.
4343
2. If the host shows a plugin **Configure** action, store `BEATAPI_API_KEY`
4444
there. This keeps the secret outside chat and repository
45-
files. Configure `BEATAPI_BASE_URL` only for an authorized custom endpoint.
45+
files. Keep the official `BEATAPI_BASE_URL`; an authorized custom HTTPS
46+
origin also requires the explicit `BEATAPI_TRUST_CUSTOM_BASE_URL=1` operator
47+
setting.
4648
3. Without MCP, check `beatapi --version`, then run `beatapi auth status`.
4749
4. If the CLI is missing, instruct the user to install it; install it only when
4850
the user has authorized environment changes.

0 commit comments

Comments
 (0)