trusted gatewayが外部A2A requestを受け, incoming Forwardedをすべて置換し, authenticated transportでForwarded: for=198.51.100.24;proto=https;host=agent.exampleをbackendへ送ります. backendはこの値をagent runtime, grant holder, approved task, delegation chainの証拠として扱う案です.
**解説:**
A: sanitizationとauthenticatedなgateway-to-backend transportによりgatewayの観測をboundary内で信頼できても, fieldに新しいapplication semanticsは加わりません.
B: RFC 7239はagent identityもgrant possessionも証明しません.
C: Sections 4, 5, 8.1はforwarding metadataとintegrity上の限界を定義します. 独立したapplication claimはA2A profile, credential validation, sender-constraining, task policy, delegation ruleで確立する必要があります.
D: Section 4はrequest fieldをforwarding proxyとreverse proxyの両方へ適用します. 禁止するのはresponseでの利用です.