fix(web): reject credentialed search redirects

This commit is contained in:
Tianyi Cui
2026-07-19 21:32:23 +08:00
parent f84092045c
commit 5e0e4b2401
10 changed files with 135 additions and 6 deletions
+2 -1
View File
@@ -80,7 +80,7 @@ export function mapExaResponse(response: ExaSearchResponse): WebSearchResult {
return { sources, truncated: false }
}
/** The Exa-backed search provider. */
/** The Exa-backed search provider; HTTP redirects fail as `WEB_PROVIDER_ERROR`. */
export class ExaSearchProvider implements WebSearchProvider {
readonly id = EXA_PROVIDER_ID
@@ -100,6 +100,7 @@ export class ExaSearchProvider implements WebSearchProvider {
try {
response = await fetch(`${this.options.baseURL}/search`, {
method: 'POST',
redirect: 'error',
headers: {
'authorization': `Bearer ${this.options.apiKey}`,
'content-type': 'application/json',