MODULE / 01
Read-only first
The default policy follows same-origin navigation, tabs, and low-risk controls. Submits, destructive labels, uploads, uncertain forms, and external origins are blocked or deferred.
- Public-network targets by default
- URL and DNS policy enforced again by the worker
- Authenticated exploration requires secure transport