AID-M-009.003
Very High
Agent Identity, Delegation Lineage & Runtime Authorization
Bind gateway sessions to a verified client identity and short-lived session credential, not to a claimed client ID plus loopback source address. A browser-opened WebSocket should never inherit CLI- or node-grade authority just because it originates from
127.0.0.1.