Remote privileged request path

Remote privileged request path A workflow diagram generated by Archify. 01 / Request 02 / Classify 03 / Execute EX / Deny Arrive Classify Authorize Remote /api · JWT assertion · Request › Arrive Remote /api JWT assertion Loopback? · localhost / ::1 · Classify › Arrive Loopback? localhost / ::1 DSH handler · no JWT · Execute › Classify DSH handler no JWT Host/Origin? · trusted-host first · Classify › Classify Host/Origin? trusted-host first JWT valid? · privileged only · Classify › Authorize JWT valid? privileged only Deny · 401 or 403 · Deny › Authorize Deny 401 or 403 DSH /api · Remote + session · Execute › Authorize DSH /api Remote + session yes no fail privileged missing / invalid original handler Legend User UI Agent logic Policy

Order is fixed

  • • Host/Origin first, then JWT
  • • A valid JWT must not rewrite Host to loopback

Bypass

  • • Loopback does not require a JWT
  • • Host/Origin failure still uses the original handler