e89dd5dc3ce08220489e7c8dea5d6939141aaac6
The previous comment implied CSRF was disabled as a temporary dev convenience. Replaced it with an explanation of why it is safe with the current Authorization-header-based auth scheme, and added a clear note on when it must be re-enabled. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Description
No description provided
Languages
Python
73.1%
TypeScript
11.5%
Java
10.9%
Svelte
4.2%
Shell
0.1%