Opus advisor flagged that PR #2160's CSP-report auth carve-out covered all write methods on the path, not just POST. Currently harmless (PATCH/DELETE fall through to CSRF 403 or routing 404), but defense-in-depth — scope the bypass to its actual use case. CSP report regression suite (6 tests) still passes.
19 KiB
19 KiB