{ "feature_id": "F-097", "agent": "security", "verdict": "APPROVED", "summary": "The change only alters proxy header/body consistency; cookies remain forwarded and backend errors remain in the existing envelope.", "evidence": [ "No credentials or API keys are added to client responses", "The backoffice cookie continues to be forwarded to the backend", "Non-empty JSON requests retain their Content-Type header", "Backend returns actionable status/code without exposing provider secrets" ], "timestamp": "2026-08-20T20:32:40Z" }