fix: trim terminal bearer token so whitespace can't break the WebSocket

A trailing space in the Open Terminal bearer token broke only the
interactive terminal: HTTP calls put the token in the Authorization
header, where the spec strips trailing whitespace, so the connection
test, file listing and tool calls all worked. The terminal WebSocket
can't set headers from the browser, so it sends the token inside a JSON
auth message that preserves the space verbatim, failing auth with
[Connection closed]. Normalize the key on save so whitespace never
enters storage, and trim it in the WebSocket auth message so existing
saved configs work without re-saving.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Fixes #25613
This commit is contained in:
Classic298 2026-06-04 01:36:43 +02:00
parent 1a97751e37
commit 241c324b13
2 changed files with 3 additions and 1 deletions

View file

@ -199,6 +199,8 @@
// Remove trailing slash
url = url.replace(/\/$/, '');
// Bearer key whitespace breaks the terminal WebSocket auth (HTTP headers strip it, JSON doesn't)
key = key.trim();
// Save policy to orchestrator if applicable
if (serverType === 'orchestrator' && !direct && policyId) {

View file

@ -106,7 +106,7 @@
ws.onopen = () => {
// First-message auth (no token in URL)
if (ws) {
ws.send(JSON.stringify({ type: 'auth', token: authToken }));
ws.send(JSON.stringify({ type: 'auth', token: authToken.trim() }));
}
connected = true;
connecting = false;