dsh-route-fence-linter

Source candidate

Audits every plugin HTTP route in a profile for a browser-trust fence: plugin routes win the web server's longest-prefix match ahead of the /api gateway, so they never see its trust check and must pin the Host to loopback themselves. Grades PASS/WARN/FAIL per route and fails a fence that compares Origin to Host without pinning it (bypassable by DNS rebinding). Ships as a CLI for CI and a route_fence_scan tool.

Author: Vladimir-Kryshchenko · Security & Permissions · Catalog snapshot: 2026-09-05

What it may solve

Audits every plugin HTTP route in a profile for a browser-trust fence: plugin routes win the web server's longest-prefix match ahead of the /api gateway, so they never see its trust check and must pin the Host to loopback themselves. Grades PASS/WARN/FAIL per route and fails a fence that compares Origin to Host without pinning it (bypassable by DNS rebinding). Ships as a CLI for CI and a route_fence_scan tool.

Imported third-party catalog description; not a Registry verification conclusion.

What can currently be confirmed

Not tested

DSH compatibility

No exact-version test is available.

Not tested

Security analysis

No Registry security conclusion is available.

Not tested

Functional verification

No functional smoke evidence is available.

Not tested

Permissions

Plugin permissions have not been resolved.

Not tested

Exact artifact

Version and integrity have not been resolved.

Continue checking with the plugin manager

Describe your task in a DSH conversation and mention dsh-route-fence-linter. The plugin manager can find this candidate through Registry, then inspect its actual source and version locally.

Get the plugin manager command