Evidence record / flue
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the signals and issues that cite it, below.
WebSocket security hardening: query string stripping and requestId validation
What Changed
Two security fixes: (1) Cloudflare WebSocket attachments strip query strings and fragments before persistence, preventing URL-carried handshake credentials from being retained. (2) Agent and workflow WebSocket frames reject blank or whitespace-only requestId values, including optional agent ping IDs.
Operator Implication
Operators should no longer pass sensitive credentials in WebSocket URLs as query parameters, relying instead on secure header-based auth.
Receipt
Finding metadata
Run: 2026-06-03-weekly-digest-2026-05-28_2026-06-03-frontier-v0
Finding ID: 2026-06-02-flue-v091-websocket-security
Accepted signals
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact