Server first

Security

The framework provides safer defaults, but applications still own their data and auth decisions.

Headers

Shield can emit CSP, nosniff, referrer and permissions policy headers. The defaults avoid unsafe-eval and inline script execution.

CSRF

Form mutations should use the CSRF plugin. Public forms can still be protected because the browser receives a token before posting.

No hidden RPC

Resources are HTTP boundaries. Services and models do not receive HTTP ctx automatically.

Alpha note

The framework is public alpha. Use it for experiments and controlled apps while the contracts continue to harden.