Constrain authenticated HTTP origins and verify realization surfaces

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e76f-be98-7ae3-965d-e0b31290a4c4
This commit is contained in:
tegwick 2026-09-28 14:12:31 +02:00
parent 0f8559f442
commit e419bfe029
9 changed files with 273 additions and 8 deletions

View file

@ -366,3 +366,19 @@ checks passed, and the full suite passed **363 tests** in 153.10 seconds.
`git diff --check` is clean. Decision:
`2ecac1c5-5254-4ce9-b092-b47c3e1283a9`. No new task or workplan was opened;
T01/T06/T07 remain waiting and this workplan remains blocked.
**2026-09-28 HTTP/surface follow-up — done.** Authenticated requests and
redirects now stay on the configured HTTP(S) origin; userinfo and invalid schemes
are rejected before sending credentials. Browser sessions, generated standalone
tests and the checked-in descendant share the transport policy. Runner also
checks the driver's reported surface against scheduled permissions, recording a
surface violation and aborting if the driver omitted its own check. Pre-action
driver checks remain necessary because post-call validation cannot undo effects.
Validation: 35 new regression cases, **107 focused tests passed**, and all
**398 tests passed** in 165.81 seconds. Local HTTP receivers and synthetic tokens
verify no cross-origin credential delivery for direct targets and five redirect
codes; same-origin requests/redirects remain functional. `git diff --check` is
clean. Decision: `88490ee8-839d-40dc-affa-b00a1c68e3c5`. No new task, workplan or
dependency. T01/T06/T07 remain waiting and this workplan remains blocked.