Repository navigation
Security Fixes
HIGH
- Make API auth token REQUIRED (was optional — API was open)
- Remove unsafe-eval from production CSP
MEDIUM
- Add CSRF Origin header check for POST/PUT/DELETE
- Cap rate limiter map size to prevent memory exhaustion