Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion architecture/security-policy.md
Original file line number Diff line number Diff line change
Expand Up @@ -113,7 +113,10 @@ allowing them to continue under stale authorization. HTTP upgrades switch to
raw relay by default. A `protocol: rest` endpoint can opt in to
`websocket_credential_rewrite` for client-to-server WebSocket text messages
after an allowed `101` upgrade; server-to-client traffic and all other upgraded
protocols remain raw passthrough.
protocols remain raw passthrough. JSON-RPC and MCP endpoints refuse every
request that carries an `Upgrade` header with `403` before forwarding,
whatever the enforcement mode, because their rules apply to individual HTTP
requests and a raw relay would bypass them.

A `protocol: tcp` hostname is a connection-routing constraint, not an
application-authority boundary. Transparent capture validates the approved DNS
Expand Down
Loading
Loading