#!/bin/sh
set -eu
: "${REDROVER_URL:?Set REDROVER_URL to the application URL}"
: "${REDROVER_API_KEY:?Set REDROVER_API_KEY from your secret manager}"
case "$REDROVER_URL" in https://*|http://localhost:*|http://127.0.0.1:*) ;; *) echo 'Use HTTPS outside localhost.' >&2; exit 1;; esac
# Keep the credential out of process arguments and reject config-file metacharacters.
case "$REDROVER_API_KEY" in hk_*) ;; *) echo 'Invalid key format.' >&2; exit 1;; esac
case "$REDROVER_API_KEY" in *[!a-zA-Z0-9_-]*) echo 'Invalid key format.' >&2; exit 1;; esac
printf 'header = "X-API-Key: %s"\n' "$REDROVER_API_KEY" |
 curl --config - --fail-with-body --silent --show-error --max-time 30 \
  --header 'Accept: application/json' "${REDROVER_URL%/}/api/v1/workspaces"
# Do not use --location with credential-bearing requests. Do not blindly retry writes.
