Typed Threat Management APIs
- Add
GET /v1/sites/{site_id}/threat-posture, GraphQLnetwork.threatPosture, and the matching action read. - Preserve null for unknown posture values. GraphQL uses BigInt for large counts and millisecond timestamps; REST returns integers.
- Add the confirmed Threat Management update action with strict validation and persistence/collateral-change results. API action previews show submitted arguments; live before/after previews are available through MCP.
- Add explicit threat event category and source/destination roles without changing reporting-device identity.
- Expose the controller's advanced filtering preference in typed settings reads.
Requires Core 0.4.61. Real-controller MCP/REST/GraphQL/action read parity and approved configuration apply/readback/restore passed on Network 10.6.106. No packet-level detection claim.
Related: #385.