{"version":"2.1.235","anchor":"workerremote-permission-requests-are-validated-before-they","canonical_anchor":"workerremote-permission-requests-are-validated-before-they","heading":"Worker\/remote permission requests are validated before they can reach the dialog","tier":"internal","area":"Sessions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.235\/e\/workerremote-permission-requests-are-validated-before-they","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.235","markdown":"### Worker\/remote permission requests are validated before they can reach the dialog\n\nPermission requests from workers and remote connections are now validated before reaching the consent dialog\n\nThe transport permission dispatcher now returns a boolean, drops `can_use_tool` frames whose `request_id` is not a string (since no reply is possible), and answers structurally malformed requests with an immediate deny carrying the message \"Malformed permission request from worker\" instead of ignoring them silently. The DirectConnect socket handler gained a `routeInboundFrame` method that rejects `control_request` frames lacking a request object or a string id. The SDK message adapter similarly drops `conversation_reset` frames without a string `new_conversation_id`, and no longer tries to render a result whose `errors` field is not an array.\n\n- Area: Sessions\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 1\/5"}