Authority: Explanatory security profile · Status: Implemented candidate · Applies to: E2 · Verified against: current checkout · Source:The client supplies only an origin identifier, operation identifier, and bounded typed values. Endpoint templates, HTTPS hosts, response limits, timeouts, attribution, replay fixtures, and rate limits are reviewed catalog configuration. The application enforces:internal/labapi,internal/origincatalog,lab/deploy
- strict bounded JSON with duplicate-key and trailing-value rejection;
- the reviewed HTTPS hostname enforced for the initial request and every redirect;
- per-client, per-origin, and global concurrency limits;
- no credentialed CORS, cookies, third-party scripts, or directory listing;
- a loopback-only application listener behind Caddy;
- manifest-last proof publication and symlink rejection;
- hashed, process-local client identifiers in audit events;
- a dedicated system user, read-only application tree, and one explicit writable result directory in production.