Block a user
Fix #138: add Secure attribute to viewer cookie (vwr)
[LOW] Viewer cookie (vwr) lacks the Secure attribute
[LOW] Deletion token accepted in the URL (?token=), leaking a bearer secret into logs/history
QA passed on live palette-dev (image @sha256:813958aa..., merge commit fe75dfc on dev).
- Create flow sets short-lived HttpOnly tok_ cookie (60s); no deletion token appears in any URL…
Remove ?token= deletion-token path (#143)
[LOW] Deletion token accepted in the URL (?token=), leaking a bearer secret into logs/history
Fix #138: add Secure attribute to viewer cookie (vwr)
Settings: dark toggle above theme list; midnight card light/dark rows swapped
QA passed (#132). Verified on live palette-dev after rollout restart: dark toggle renders ABOVE the Theme heading/theme-grid in the settings menu; midnight pair card shows light variant (midnight-l…
Remove ?token= deletion-token path (#143)
Settings: dark toggle above theme list; midnight card light/dark rows swapped