- ALLOW_PURGE is now false by default; the UI shows a banner when there is
no authentication.
- Read-only role: AUTH_VIEWER_USER/AUTH_VIEWER_PASS in local mode, or
OIDC_ADMIN_GROUP in OIDC mode; changes get 403 and the admin settings
are greyed out.
- Content-Security-Policy (inline scripts allowed by hash) and other
security headers; cross-site changes are refused.
- Syslog TCP: at most SYSLOG_TCP_MAX_CONNS connections, closed after
SYSLOG_TCP_IDLE of silence; HTTP idle timeout.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>