httpgw: JSON API with structured parsing and consumer-facing endpoint filtering
- All responses use application/json; errors use {"error": "..."}
- File reads parse content by format: key=value → object, tab-separated → arrays, newline list → []string, single value → {name: value}
- /s/idx parsed into typed IdxEntry structs (id, state, cwd, backend, model)
- POST for all writes (actions/updates); PUT removed
- /s/new is POST-only (session creation)
- /s/{id}/cfg is POST (partial update)
- /s/{id}/chat is read-only
- Internal paths blocked: /, /a, /p, /m, /t, /sk, /help, /tr, /u, /x, /tmp
- Per-file blocked: systemprompt, statewait
- /s returns array of session IDs only
- Embedded OpenAPI 3.0 spec at /openapi.json
- OPTIONS handler with accurate method descriptions
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>