Artifact downloads now pass through a screening step that can stop them with a canned message.
What's wrong with this entry?
Both artifact fetch paths now run the raw status, headers and body through a shared screening step that can stop the fetch early with a canned message. It runs only for direct fetches and is skipped when the request goes through the cloud relay. The screening code and its map from reason to message live in a shared chunk, so which responses it rejects is not visible from the fetch paths themselves.
[artifact] asset fetch
Strings lifted out of the shipped bundle, so the claim above can be checked against them.