Block a user
SDK client metadata is silently rewritten on reconnect
Integrity envelopes do not survive root key rotation
Wallet-access revocation deletes by wallet_id instead of entry id
Bootstrap token RNG seeding should be made explicit
Consumed bootstrap token is not zeroized in memory
security: batch of fixes
User-agent signing endpoint accepts arbitrary client_id
Encrypted key material not bound to wallet address — cross-wallet signing possible
deps(server): version bump
RequestTracker allows arbitrary gaps across request flows
Zombie user-agent sessions can block all new client approvals
fix(user-agent): zombie sessions #74