Evidence record / flue

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the signals and issues that cite it, below.

WebSocket security hardening: query string stripping and requestId validation

What Changed

Two security fixes: (1) Cloudflare WebSocket attachments strip query strings and fragments before persistence, preventing URL-carried handshake credentials from being retained. (2) Agent and workflow WebSocket frames reject blank or whitespace-only requestId values, including optional agent ping IDs.

Operator Implication

Operators should no longer pass sensitive credentials in WebSocket URLs as query parameters, relying instead on secure header-based auth.

Receipt

Finding metadata

Run: 2026-06-03-weekly-digest-2026-05-28_2026-06-03-frontier-v0

Finding ID: 2026-06-02-flue-v091-websocket-security

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact