Skip to main content

Module security

Module security 

Source
Expand description

HTTP security utilities.

SecurityContext propagation over HTTP uses a single header, Authorization: Bearer <jwt>, carrying the original tenant-plane JWT. The token is forwarded as-is across hops and re-validated at every hop — there is no trusted-peer fast path (zero-trust). No binary x-secctx-bin encoding is used over HTTP.

Constants§

ERROR_BODY_PREVIEW_LIMIT
Maximum body preview size for error messages (8KB).

Functions§

attach_bearer_http
Attach the tenant-plane JWT from secctx to an outgoing request as Authorization: Bearer <jwt>.
attach_internal_token_http
Attach a platform-plane internal token to an outgoing request as the X-ToolKit-Internal-Token header.