docs(protect-edge): explain HTML-vs-JSON path types in the overview - #52
Merged
Conversation
Adds a "Protecting HTML pages vs JSON APIs" section to the edge integration overview. Explains: - HTML paths: cookie-less first-visit passes through so the Protect script can load and create a session; subsequent requests hit the verdict path. - JSON paths: cookie-less request 401s with X-Prosopo-Status: no-session; the Protect script intercepts, creates a session, and replays. Never passes through — no HTML shell to bootstrap from. - How to configure via defaultPathType + per-endpoint rules on the Prosopo dashboard, and why this closes the Accept-header spoof bypass. - Which mode fits which kind of site (server-rendered, SPA, pure API), with a table. Verified: astro check 0 errors. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
✅ Deploy Preview for peaceful-pothos-9e62ce ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
"HTML SPA shell" was internal terminology and confusing for readers who aren't building a single-page app. Reword to "HTML page" and "HTML pages" throughout. The "Single-page app" row in the mode-fit table stays — it's how most devs describe their own project. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a new "Protecting HTML pages vs JSON APIs" section to the edge integration overview at `/protect-edge/`. Explains:
Test plan
🤖 Generated with Claude Code