Summary
Add IContextValidator to vet inbound context/header values before the manager rebuilds a context, plus a SizeBoundaryValidator that rejects empty, oversized, or malformed values.
Goal
Make header/queue ingestion safe — validate on entry, treat as untrusted surface, and never trust that headers exist.
Problem
Propagation examples accept inbound headers and immediately rebuild context. Spoofed/oversized/garbled values flow straight into BeginContext. There is no uniform validation gate, so each consumer re-implements the check (see 1.1 spoofing risk and 1.8).
Scope & Results
Design Expectations
Acceptance Criteria
Non-Goals
- No cryptographic authenticity (HMAC/signature is a later adapter).
- No changes to outbound propagation or core runtime.
Summary
Add
IContextValidatorto vet inbound context/header values before the manager rebuilds a context, plus aSizeBoundaryValidatorthat rejects empty, oversized, or malformed values.Goal
Make header/queue ingestion safe — validate on entry, treat as untrusted surface, and never trust that headers exist.
Problem
Propagation examples accept inbound headers and immediately rebuild context. Spoofed/oversized/garbled values flow straight into
BeginContext. There is no uniform validation gate, so each consumer re-implements the check (see 1.1 spoofing risk and 1.8).Scope & Results
IContextValidatorabstraction withValidate(..., out errors).SizeBoundaryValidator: empty, over-limit, and malformed-value detection.Design Expectations
BeginContext.Acceptance Criteria
BeginContext.Non-Goals