Server first
Security
The framework provides safer defaults, but applications still own their data and auth decisions.
Headers
Shield can emit CSP, nosniff, referrer and permissions policy headers. The defaults avoid unsafe-eval and inline script execution.
CSRF
Form mutations should use the CSRF plugin. Public forms can still be protected because the browser receives a token before posting.
No hidden RPC
Resources are HTTP boundaries. Services and models do not receive HTTP ctx automatically.
Alpha note
The framework is public alpha. Use it for experiments and controlled apps while the contracts continue to harden.