Under the hood
Managed config validation now rejects entries that look like they leak credentials.
Managed-config validation for the hosted control plane (hybrid channel) now rejects entries that look like they contain a credential header, that carry disallowed query strings or fragments on base URLs, or that exceed array-length bounds. Rejected entries are not stored, and the error points admins to a helper script instead.