Block a user
Security: enforce HTTPS for agent-server communication
Security triage 2026-04-17: this ticket is now the prerequisite for the SaaS rollout security story. Without HTTPS enforced here, the per-deployment scoped tokens delivered by cameleer-server #129…
Security: sign all SSE commands (not just config-update)
Security: sign all SSE commands (not just config-update)
Closing as superseded during 2026-04-17 security triage.
SSE command integrity is covered once two things land: (a) HTTPS enforcement for the agent-server channel (#52), (b) scoped JWTs with…
Security: sign startup config API response
Security: sign startup config API response
Closing as split/superseded during 2026-04-17 security triage.
Response signing — superseded by HTTPS enforcement (#52) + JWT auth + per-deployment scoped tokens (cameleer-server #129). Once…
Security: tamper-protect on-disk cached application config