mirror of
https://github.com/OrcaSlicer/OrcaSlicer.git
synced 2026-10-07 07:41:06 +00:00
# Description The default Orca Cloud API URL omits its scheme, so libcurl interprets it as HTTP and follows the server redirect to HTTPS. Recent libcurl versions intentionally do not forward the `Authorization` header across protocol/port-changing redirects, causing Orca Cloud profile sync to receive HTTP 401 `missing_authorization` responses and eventually log the user out. Use the HTTPS API URL directly. Besides restoring sync with current libcurl versions, this improves security by preventing the bearer access token from being sent in the initial unencrypted HTTP request. # Screenshots/Recordings/Graphs N/A — no UI changes. ## Tests - `git diff --check` - Confirmed with current libcurl that the scheme-less URL redirects and loses the authorization header, while the direct HTTPS URL retains it