The transport permission dispatcher now returns a boolean, drops can_use_tool frames whose request_id is not a string (since no reply is possible), and answers structurally malformed requests with an immediate deny carrying the message "Malformed permission request from worker" instead of ignoring them silently. The DirectConnect socket handler gained a routeInboundFrame method that rejects control_request frames lacking a request object or a string id. The SDK message adapter similarly drops conversation_reset frames without a string new_conversation_id, and no longer tries to render a result whose errors field is not an array.
Worker/remote permission requests are validated before they can reach the dialog
Permission requests from workers and remote connections are now validated before reaching the consent dialog
Under the hoodTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SessionsArea: what it touches
Bug FixesKind: in v2.1.235,
Bug FixesSection of the release