Expand description
HTTP security utilities.
SecurityContext propagation over HTTP uses a single header,
Authorization: Bearer <jwt>, carrying the original tenant-plane JWT. The
token is forwarded as-is across hops and re-validated at every hop —
there is no trusted-peer fast path (zero-trust). No binary
x-secctx-bin encoding is used over HTTP.
Constants§
- ERROR_
BODY_ PREVIEW_ LIMIT - Maximum body preview size for error messages (8KB).
Functions§
- attach_
bearer_ http - Attach the tenant-plane JWT from
secctxto an outgoing request asAuthorization: Bearer <jwt>. - attach_
internal_ token_ http - Attach a platform-plane internal
tokento an outgoing request as theX-ToolKit-Internal-Tokenheader.