# Security Policy This plugin is for local DSH Web use. ## Local endpoints The `/archived/api/*` endpoints accept `POST` requests from loopback / same-origin pages only. File deletion also checks that the target is inside a registered workspace and belongs to the selected session's produced-file list. ## Reporting Use for bug reports. Include your DSH version and reproduction steps. Do not upload private session logs, output files, API keys, or credentials.