wiki: fix wrong auth/OIDC recipes; add download + CWA learnings Accuracy fixes (current recipes are wrong and harmful): - Recover-admin: remove the bcrypt password-hash recipe (Bindery is argon2id-only; a bcrypt hash is silently rejected). Replace with the admin reset-password endpoint and the delete-users setup-wizard path. - Fix the user-role endpoint everywhere: PUT /auth/users/{id}/role (not the bare PUT /auth/users/{id}). - Rotate-OIDC-secrets: the per-provider-id PUT/POST endpoints do not exist; the API is a whole-array GET/PUT. Rewrote to read-modify-write the full array, with a warning that a single-provider PUT deletes all other providers. Fix session-secret rotate path to POST /auth/session-secret/rotate. - Troubleshooting: multi-user 'User A sees User B data' is the documented default (BINDERY_ENFORCE_TENANCY defaults off), not a bug. Added learnings: - SAB/NZBGet now upload NZB content (addfile / base64 append) so the client never needs to reach the indexer. - History tab now records scheduler auto-grabs (#938). - 'connection refused' diagnostics: interface-binding / host-firewall framing (not Docker-subnet). - CWA ingest folder (cwa.ingest_path) + External import mode workaround for duplicate book rows; noted #940/#941 as not-yet-shipped.
Add Phase 3 multi-user howto set (v1.0) - Howto-Migrate-to-multi-user.md: backup, dry-run, upgrade, rollback, migration 019 troubleshooting - Howto-Add-a-second-user.md: local/OIDC/proxy users, roles, promote/demote, delete safely - Howto-Recover-admin-access.md: API recovery, direct DB update (Docker + K8s), password reset, API key retrieval - Howto-CSRF-tokens.md: session-cookie preflight, migration from X-Requested-With, API-key exemption Update Home.md and _Sidebar.md with "Multi-user — v1.0.0" section.