Pass the API key via x-goog-api-key HTTP header instead of the URL query parameter to prevent credential leakage in proxy logs, web server access logs, and monitoring systems. Resolves: #47 (CVSS 5.3, OWASP A09:2021) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| ratelimit.go | ||
| ratelimit_test.go | ||