0.5.1
Security and consistency fixes.
- Web GUI: POST endpoints now require a per-session token (embedded in
the page, sent as a header) — previously a drive-by webpage could
silently submit turns and write arbitrary files via the save endpoint - The memory-contamination warning no longer shows for the offline
PseudoBot (only for real backends); non-loopback bindings print a loud
warning - TUI: input is disabled while a send is in flight (Session is not
thread-safe) - version metadata sync fix
Emulation, not diagnosis.