fix(ws): harden Responses connection lifecycle

Revalidate control policy per turn, isolate downstream credentials, and make planner/turn ownership cancellation-safe.

Preserve opaque protocol events, align configurable timeout semantics, and extend end-to-end security and settlement coverage.
This commit is contained in:
ZheFox
2026-08-17 18:50:29 +08:00
parent 4a0775c4ea
commit c8118edf36
42 changed files with 4017 additions and 1276 deletions
@@ -12,9 +12,11 @@ mod admission;
mod binding;
mod client;
mod connection;
mod control;
mod frame;
mod lifecycle;
mod observation;
mod ownership;
mod quota;
mod redaction;
mod relay_policy;
@@ -61,5 +63,4 @@ pub(crate) async fn responses_websocket(
const RESPONSES_WEBSOCKET_INGRESS_SPEC: WebSocketIngressSpec = WebSocketIngressSpec {
route_unavailable_message: "WebSocket route is unavailable",
ip_whitelist_failure_event_name: "responses_websocket_ip_whitelist_check_failed",
};