Captain custom tools configured with API key authentication now send the configured key in the requested HTTP header. Existing tools begin working without needing to be recreated or reconfigured, while credentials remain protected across redirects. ## How to reproduce 1. Create a Captain custom tool using API Key authentication. 2. Configure `X-API-Key` as the header name and save the tool. 3. Invoke the tool and inspect the incoming request. 4. Before this change, the API key header is absent; after this change, the configured endpoint receives it. ## What changed The UI persists API key authentication as `name` and `key`, but the request builder also required an unused `location: header` property. The request builder now treats API key authentication as header-based, matching the only mode exposed by the UI. Custom authentication headers are also registered as sensitive with `SafeFetch`. They are retained for the configured endpoint and same-origin redirects, but stripped when a redirect crosses origins to prevent credential leakage. Factory, request, and redirect specs cover the real UI payload and both public and private-network fetch paths.
52 lines
1.5 KiB
Ruby
52 lines
1.5 KiB
Ruby
FactoryBot.define do
|
|
factory :captain_custom_tool, class: 'Captain::CustomTool' do
|
|
sequence(:title) { |n| "Custom Tool #{n}" }
|
|
description { 'A custom HTTP tool for external API integration' }
|
|
endpoint_url { 'https://api.example.com/endpoint' }
|
|
http_method { 'GET' }
|
|
auth_type { 'none' }
|
|
auth_config { {} }
|
|
param_schema { [] }
|
|
enabled { true }
|
|
association :account
|
|
|
|
trait :with_post do
|
|
http_method { 'POST' }
|
|
request_template { '{ "key": "{{ value }}" }' }
|
|
end
|
|
|
|
trait :with_bearer_auth do
|
|
auth_type { 'bearer' }
|
|
auth_config { { token: 'test_bearer_token_123' } }
|
|
end
|
|
|
|
trait :with_basic_auth do
|
|
auth_type { 'basic' }
|
|
auth_config { { username: 'test_user', password: 'test_pass' } }
|
|
end
|
|
|
|
trait :with_api_key do
|
|
auth_type { 'api_key' }
|
|
auth_config { { key: 'test_api_key', name: 'X-API-Key' } }
|
|
end
|
|
|
|
trait :with_templates do
|
|
request_template { '{ "order_id": "{{ order_id }}", "source": "chatwoot" }' }
|
|
response_template { 'Order status: {{ response.status }}' }
|
|
end
|
|
|
|
trait :with_params do
|
|
param_schema do
|
|
[
|
|
{ 'name' => 'order_id', 'type' => 'string', 'description' => 'The order ID', 'required' => true },
|
|
{ 'name' => 'include_details', 'type' => 'boolean', 'description' => 'Include order details', 'required' => false }
|
|
]
|
|
end
|
|
end
|
|
|
|
trait :disabled do
|
|
enabled { false }
|
|
end
|
|
end
|
|
end
|