2 months ago
5fd9aa0Introduces a native-client loopback JSON-RPC endpoint at `POST /rpc` with sticky per-client sessions via `X-Cowork-Client-Id`, plus loopback-only access checks and browser-token protection parity with `/ws`/`/cowork/*`. Refactors shared HTTP JSON-RPC connection/payload handling out of the H3 server, extends transport metadata to include `http`, updates server startup output and docs for `COWORK_RPC_URL`, adds `dev:rpc`, and adds coverage for handshake/state behavior and header enforcement in new loopback tests.
Parent97582ad