Expand description
Core-side gate for the edge/core split. When the server runs with
--role core, every request must carry the shared secret the edge adds
(X-M4A-Edge-Secret). The tunnel and a firewall allowlist are the first
line; this header is the second, so a stray process on the tunnel network
cannot talk to the core. The secret comes from the environment and is never
logged.
Constants§
- EDGE_
SECRET_ HEADER - Header name carrying the shared secret edge -> core.
Functions§
- require_
edge_ secret - Wraps
routerso requests without the right secret get a Matrix-shaped 401. - require_
link_ token - Barrier token gate for a standalone core reached directly by a product server
(
M4A_LINK_TOKEN): every request outside the public protocol surfaces must carryx-m4a-link-token. The header is removed before routing.