Vaadin Push endpoint origin validation configuration for multi‑tenant deployments
Goal Enable per‑session origin whitelisting for Vaadin Push WebSocket connections so that a single server can safely serve Push to multiple hostnames in a multi‑tenant environment. Vaadin Push currently relies on the browser same‑origin policy and validates the TLS certificate only against the server hostname; there is no documented API or server‑side config