scout_request
Call the app's API as the current session to confirm that hidden or disabled controls are truly refused by the server, returning status, timing, and key headers.
Instructions
Call the app's own API as this session, with the UI bypassed — the check that turns a hidden or disabled control into a proven refusal. A button that is not shown proves nothing; the same action refused by the server does. The fetch runs IN the page, so it carries the session's cookies and replays the Authorization header the app itself last sent, and it passes through the same interception the write policy is enforced on: in safe-write a mutation on a record this session did not create is refused here exactly as it would be for a click, and that refusal is the engine's safety net, not a finding. Returns the status line, the timing, the headers that decide whether two responses are truly identical (content-type, location, www-authenticate, retry-after, cache-control), and the body. Unlike a shell call, every request is recorded in the run's trail and its signature is what a finding should quote. Paths are fenced to the attached origin: use another session to reach another host.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| body | No | Request body, sent as application/json unless a content-type header is given | |
| path | Yes | Path on the attached origin, e.g. /api/things/12, or a full URL on that same origin | |
| task | No | What you are DOING right now, in a few words: the action, not the acceptance criteria. "Filtering the documents register by status", "Filling the deviation form with invalid dates", "Signing in as QA_Team" — NOT "§2.4 filtering narrows the set and the filter is reflected in the URL", which is what you are CHECKING, not what you are doing. Naming the item you are on is fine ("§2.4: filtering the documents register"); keep the rest to what a colleague would see over your shoulder. It stays set until you pass a different one, so a batch costs a few words, not one per call. Required on the tools that act unless a journey or an earlier call already set one. | |
| method | No | Default GET | |
| headers | No | Extra headers. One given here wins over the app's own, which is how a session tests a different or absent credential. | |
| session | No | Target this session directly instead of the active one — pass it explicitly when dispatching to MULTIPLE sessions in one turn (e.g. two scout_click calls with different `session`), which then run CONCURRENTLY rather than queueing. Omit for single-session sequential use. | |
| objective | No | Old name for `task` (2.0). Prefer `task`. |