🔑 Make API key optional for server-side proxy support #11
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
This PR makes the API key optional in the Endereco JavaScript SDK, allowing systems to proxy requests through their own servers and add the API key server-side for enhanced security.
Changes Made
X-Auth-Keyonly whenapiKeyis configuredAddressExtension.js- ModifiedgetAddressMetafunctionEmailCheckExtension.js- ModifiedcheckEmailfunctionPhoneCheckExtension.js- ModifiedcheckPhonefunctionNameCheckExtension.js- ModifiedcheckPersonfunctionTesting
Related Issues
This change enables server-side proxy patterns for systems that need to keep API keys secret and add them via backend proxy services.
This enhancement complements the server-side proxy implementation in the Shopware 6 plugin (PR #76), where API keys are stored securely in the backend and requests are proxied through the shop's server. With this SDK change, the Shopware plugin and similar implementations can now operate without exposing API keys in the frontend.
Implementation Details
When
config.apiKeyis not provided or is empty, the SDK will make requests without theX-Auth-Keyheader. This allows backend systems to:Existing implementations with client-side API keys will continue to work exactly as before.