-
server: adopt lint block, fix clippy, fmt
-
server: flip OAuth empty-scope to userinfo; validate build signing_key_path
-
audit Run 16 Phase 1: Security axis A- -> A
-
security: close OAuth silent-consent gap, ClamAV fail-open observability, 7z/RAR + blame hardening
-
OAuth maturation + HMAC method+path+nonce (close MT S13)