{"record":{"id":"1cbd9982083db6e2","repo":"Hmbown/CodeWhale","slug":"refusing-insecure-base-url-display-base-url-loopback-hosts","errorCode":null,"errorMessage":"Refusing insecure base URL '{display_base_url}'.\n\nLoopback hosts (localhost, 127.0.0.1, [::1]) are auto-allowed.\nFor one trusted local provider (LAN, llama.cpp on a private IP, etc.) set\n`allow_insecure_http = true` under its `[providers.<name>]` table in config.toml.\nTo allow it for every provider in this shell instead, set the env var\n{ALLOW_INSECURE_HTTP_ENV}=1 and re-run.","messagePattern":"Refusing insecure base URL '(.+?)'\\.\n\nLoopback hosts \\(localhost, 127\\.0\\.0\\.1, \\[::1\\]\\) are auto-allowed\\.\nFor one trusted local provider \\(LAN, llama\\.cpp on a private IP, etc\\.\\) set\n`allow_insecure_http = true` under its `\\[providers\\.<name>\\]` table in config\\.toml\\.\nTo allow it for every provider in this shell instead, set the env var\n(.+?)=1 and re-run\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/tui/src/client.rs","lineNumber":1028,"sourceCode":"        );\n        return Ok(());\n    }\n\n    if parsed.scheme() == \"http\"\n        && std::env::var(ALLOW_INSECURE_HTTP_ENV)\n            .or_else(|_| std::env::var(LEGACY_ALLOW_INSECURE_HTTP_ENV))\n            .ok()\n            .as_deref()\n            .is_some_and(|v| v == \"1\" || v.eq_ignore_ascii_case(\"true\"))\n    {\n        logging::warn(format!(\n            \"Using insecure HTTP base URL because {ALLOW_INSECURE_HTTP_ENV} is set\"\n        ));\n        return Ok(());\n    }\n\n    if parsed.scheme() == \"http\" {\n        anyhow::bail!(\n            \"Refusing insecure base URL '{display_base_url}'.\\n\\\n             \\n\\\n             Loopback hosts (localhost, 127.0.0.1, [::1]) are auto-allowed.\\n\\\n             For one trusted local provider (LAN, llama.cpp on a private IP, etc.) set\\n\\\n             `allow_insecure_http = true` under its `[providers.<name>]` table in config.toml.\\n\\\n             To allow it for every provider in this shell instead, set the env var\\n\\\n             `{ALLOW_INSECURE_HTTP_ENV}=1` and re-run.\",\n        );\n    }\n\n    anyhow::bail!(\n        \"Refusing base URL '{display_base_url}': only HTTPS (or explicitly allowed HTTP) URLs are supported.\",\n    )\n}\n\npub(crate) fn redact_url_for_display(url: &str) -> String {\n    let Ok(mut parsed) = reqwest::Url::parse(url) else {\n        return url.to_string();","sourceCodeStart":1010,"sourceCodeEnd":1046,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/433685b2024e7bc4c99e1e2e326bcad39b4d9d65/crates/tui/src/client.rs#L1010-L1046","documentation":"The client refuses plain-HTTP base URLs by default to prevent credentials and chat content from being sent unencrypted. Loopback hosts (localhost, 127.0.0.1, [::1]) are exempted. The error explains the three sanctioned opt-outs: per-provider allow_insecure_http in config.toml, or the shell-wide env var.","triggerScenarios":"Configuring a provider's base_url with an http:// scheme pointing at a non-loopback host (e.g. http://192.168.1.10:8080) without allow_insecure_http=true for that provider and without ALLOW_INSECURE_HTTP_ENV=1 set.","commonSituations":"Pointing at a LAN llama.cpp/llama-server or other local inference server on a private IP; copying a provider config written for a local HTTP endpoint; typos like http:// when the provider actually serves HTTPS.","solutions":["Use https:// in the provider's base_url if the server supports TLS.","Set allow_insecure_http = true under [providers.<name>] in config.toml for that one trusted local provider.","Set the ALLOW_INSECURE_HTTP env var to 1 to allow HTTP for every provider in this shell session.","If the host is loopback, switch to http://localhost/... so it is auto-allowed."],"exampleFix":"// before (config.toml)\n[providers.llamacpp]\nbase_url = \"http://192.168.1.10:8080\"\n// after\n[providers.llamacpp]\nbase_url = \"http://192.168.1.10:8080\"\nallow_insecure_http = true","handlingStrategy":"validation","validationCode":"let url = reqwest::Url::parse(base_url)?;\nlet loopback = matches!(url.host_str(), Some(h) if h == \"localhost\" || h.starts_with(\"127.\") || h == \"[::1]\");\nif url.scheme() == \"http\" && !loopback && !allow_insecure_http {\n    return Err(\"http base URL requires allow_insecure_http or a loopback host\");\n}","typeGuard":null,"tryCatchPattern":"match client_err {\n    e if e.to_string().contains(\"Refusing insecure base URL\") => {\n        // switch to https or set allow_insecure_http for this provider\n    }\n    other => return Err(other),\n}","preventionTips":["Default all provider base_urls to https://.","Only enable allow_insecure_http for loopback/LAN dev servers you control.","Never set the shell-wide insecure HTTP env var in production shells.","Audit config.toml for http:// URLs before deploying."],"tags":["network","security","tls","configuration"],"backgroundTag":"invalid-url","analyzedSha":"433685b2024e7bc4c99e1e2e326bcad39b4d9d65","analyzedAt":"2026-09-15T12:24:24.634Z","contentChangedAt":"2026-09-15T12:24:24.634Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}