- RFC 8291 aes128gcm encryption from crypto/ecdh, crypto/hkdf and AES-GCM,
matching the RFC 8291 Appendix A vector byte for byte
- RFC 8292 vapid t=<ES256 JWT>, k=<key> header (aud origin, exp +12h, sub)
- Pusher, Subscription, SendOptions, SubscriptionSource, Service and From
reading push.* (enabled, keys, subject, ttl, allowed_hosts)
- sends only to https endpoints on push.allowed_hosts, checked before
dialing, and never follows redirects; 404/410 map to ErrSubscriptionGone
- module README and root modules row