-
Add CSP violation reporting
-
server: adopt lint block, fix clippy, fmt
-
Bump the tower/axum middleware cluster (server, kberg)
-
Format the tree with rustfmt and add the lint + supply-chain gates
-
Decompose AppState Phase 2: api ownership-helper foundation
-
server: attach per-IP rate limit to guest download route
-
Remediate audit Run 21 findings across server
-
Close security gaps from ultra-fuzz Run 10 (Security axis)
-
Add git personal-access-tokens for HTTPS clone and push
-
server: Tier 0 creator theming + fold in Run 18 storage work
-
server: replace global CSRF allowlist with per-route posture helpers
-
phase 3: trial presets, promo redemption tracking, scan-flag surfacing
-
exorcise: B15a routes/api/ doc comments
-
Add Email validated newtype, replace ad-hoc email handling