- Rotate the session token at the OIDC callback and restore the full
lifetime; cap pre-auth sessions at 15 minutes and write no session
for bare anonymous requests
- Treat db-dsn as a secret: accept db-dsn-file, log only host, port,
database and user, and never echo a malformed DSN in an error
- Guard the logout callback with a state cookie so a forged visit
cannot end a live session
- Collapse FedWiki site actions on a foreign tenant's domain to the
not-found answer, as for a domain that does not exist