Block a user
docs: design for optional client-side E2E encryption (issue #39)
Clamp expires_in at API boundary (#60)
Admin key endpoint: per-IP rate limiting and lockout (#66)
Search: loading indicator and performance note (#32)
docs: cookie-based preferences and access keys design (#30)
Closes #30 (design portion; implementation tracked separately when scheduled).