Skip to content

Keep browser-session boostrap secrets out of urls#14

Open
jescalan wants to merge 1 commit intomainfrom
je.browser-bootstrap-hardening
Open

Keep browser-session boostrap secrets out of urls#14
jescalan wants to merge 1 commit intomainfrom
je.browser-bootstrap-hardening

Conversation

@jescalan
Copy link
Contributor

Hardens the browser-session bootstrap flow by updating the spec to keep bearer-equivalent initialization material out of URLs and adding an optional initialization_request shape for POST-based initialization. It also updates the Service SDK to pass that field through, marks browser-session redemption responses as Cache-Control: no-store, aligns the harness skill guidance, and adds regression coverage for the new response shape.

@jescalan jescalan requested a review from colinclerk March 18, 2026 22:36
@vercel
Copy link

vercel bot commented Mar 18, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
agentpass Ready Ready Preview, Comment Mar 18, 2026 10:36pm

Request Review

@jescalan jescalan changed the title keep browser-session boostrap secrets out of urls Keep browser-session boostrap secrets out of urls Mar 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant