You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 06ce88c
Browse filesBrowse the repository at this point in the historyBrowse files
feat(zig-api): wire proven_header_has_crlf CRLF-injection guard into gnosis
Add safeHeaderDefault helper that calls proven_header_has_crlf
(formally-verified from libproven_ffi) to validate response headers
for CRLF injection before serialisation.
Integrate check into writeResponse() — if Content-Type header contains
CRLF or proven returns an error, refuse entire response with 500 error
(fail-closed policy).
Extern declarations for proven_header_has_crlf match proven.h C ABI.
Comments document the proven → zig-api → gnosis chaining.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
0 commit comments