chore: harden Somnia session frontend - #27
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Isolated preview QATested the two Vercel previews created for this draft PR.
The branch-specific Somnia session-key variables currently remain scoped to Sponsorship-policy review
No production, support-branch, domain, or existing URL settings were changed. |
Isolated preview QA update
Production and the existing support preview were not changed. |
Strict session-permission verificationAdded commit
Verification completed:
No production URL, support URL, contract address, or Vercel environment scope was changed. A fresh wallet-backed Session Keys creation/revocation pass remains the final manual QA step. |
Summary
viemandwagmito their current compatible patch releasesaxios,js-yaml, andwsX-Powered-Byresponse headerVerification
/onchainruntime checks returned HTTP 200 with the expected security headersnpm audit: 26 moderate, 0 high, 0 criticalGuardrails
feat/somnia-session-keys)4ba8ea2unsafe-inline; nonce-based CSP should be evaluated separately because it changes rendering and deployment behavior