Bind CLI proxy identity to the authenticated socket principal
Author: joshuajbouwCreated Sep 15, 2026Updated Sep 15, 2026
The CLI proxy currently binds a connection from the first JSON message's principal field. Bind it instead to the principal Astrid authenticated for the accepted socket, reject unauthenticated connections, and treat any payload principal as a consistency check only. Preserve same-principal session demultiplexing and the new request-owner approval routing.
Source: unicity-aos/aos-ce