Default-deny
The policy model is default-deny. If a new endpoint is added without a policy mapping, the gateway rejects all requests to it. This catches accidental over-exposure during development. The frontend will surface a policy_missing error during build-time integration tests if a new API call is made without a policy entry in the table.
1 lesson reference ← Back to glossary
Where it appears
Read the term in context.
Each row is a lesson that uses this term. The lesson where it first appears is the canonical definition.