fix: harden CLI tools against credential leakage

Move Supermetrics API key from query string to x-api-key header.
Mask ZoomInfo JWT by default in auth command (use --show-token to reveal).

Cherry-picked from #201.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Corey Haines
2026-04-21 13:32:33 -07:00
parent c8e2d11556
commit 9698318a30
2 changed files with 17 additions and 9 deletions
+8 -7
View File
@@ -9,17 +9,18 @@ if (!API_KEY) {
}
async function api(method, path, body) {
const separator = path.includes('?') ? '&' : '?'
const url = `${BASE_URL}${path}${separator}api_key=${API_KEY}`
const url = `${BASE_URL}${path}`
const headers = {
'Content-Type': 'application/json',
'Accept': 'application/json',
'x-api-key': API_KEY,
}
if (args['dry-run']) {
return { _dry_run: true, method, url: url.replace(API_KEY, '***'), headers: { 'Content-Type': 'application/json', 'Accept': 'application/json' }, body: body || undefined }
return { _dry_run: true, method, url, headers: { ...headers, 'x-api-key': '***' }, body: body || undefined }
}
const res = await fetch(url, {
method,
headers: {
'Content-Type': 'application/json',
'Accept': 'application/json',
},
headers,
body: body ? JSON.stringify(body) : undefined,
})
const text = await res.text()