Goal
Close the remaining security blockers from native Arbiter task #62.
Scope
- Reject all alternate numeric and untrusted DNS hosts before authenticated requests; use a strict trusted deployment policy or resolution/pinning that rejects private, loopback, link-local, reserved, and metadata targets.
- Revalidate redirect origin, scheme, and
/api/v1 path before forwarding Authorization.
- Replace pathname check-then-use research I/O with descriptor-anchored no-follow operations for reads, writes, and atomic replacement; cover case/research directory swaps.
- Preserve plugin parity and existing native workflow behavior.
Acceptance
Non-goals
- No real Arbiter study creation.
- No Data Navigator retirement in this task.
Goal
Close the remaining security blockers from native Arbiter task #62.
Scope
/api/v1path before forwarding Authorization.Acceptance
Non-goals