158b5323d3
Capture conscious tradeoffs and hardening candidates that go beyond the mandatory 7.6 requirements: reverse-proxy rate-limit keying, missing security response headers, CSRF/SameSite stance, __Host- cookie prefix, session/ops notes, and the gap that CI does not run go test. None are compliance defects; each is a decide-later item. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>