2026-09-19T07:14:05Z boundary-hardening Validate complete provider and merged-policy documents before persistence, safely project JavaScript prototype-shaped parameter keys, and canonicalize legacy set-valued storage fields Final independent review found that per-fragment validation missed aggregate limits, TypeScript object inheritance could erase untrusted map keys, and stricter public uniqueness rules could reject status-only rewrites of older equivalent records provider mixed-batch and 1025-rule regressions; TypeScript __proto__/constructor regression; sandbox and provider durable rewrite regressions All write paths now fail before partial persistence, SDK projection retains every own key without prototype mutation, and legacy duplicate ports or matcher alternatives preserve their enforcement meaning
0 commit comments