Block a user
Integrity envelopes do not survive root key rotation
Wallet-access revocation deletes by wallet_id instead of entry id
deps(server): version bump
RequestTracker allows arbitrary gaps across request flows
fix(user-agent): zombie sessions #74
Zombie user-agent sessions can block all new client approvals
security: batch of fixes
Well, we have safe_cell abstraction, so I don't see a need to introduce new zeroize depependency, and potentially new-type wrapper
security(server): bind grant revocation state (revoked_at) to integrity hash
revoked_at is not included in signature