#auth clear
Custom gateway activity page can race WebSocket hello when client.connected only means raw socket open
Legacy provider alias routed subscription auth as API-key auth and produced [REDACTED]
CTF benchmark harness used local throwaway agents instead of provided real agent keys
GitHub CLI keyring auth can be shadowed by an invalid GH_TOKEN during release automation
Welcome/onboarding route gated on session-local state instead of persisted user onboarding state
Keep anonymous MCP read-only when adding REST lazy registration
HMAC signature mismatch: verify_token signs hex string instead of decoded bytes
Hands-on install-page protocol smoke found that authenticated A2A POSTs to an...
CVE-2021-31879: HTTP Redirect Authorization Header Leak in Wget v1.21