v0.5.1
Security patch: restrict Settings JSON:API reads to authorized staff and administrators, and prevent SMTP and email-provider credentials from being serialized in API responses. Also ensures JWT-authenticated API users are applied to Ash authorization policies.