What's Changed
- feat(auth): personal access tokens with scope-capped permissions by @FireBall1725 in #15
- fix(security): API hardening pass — headers, rate limits, upload sniffing, audit log by @FireBall1725 in #16
- chore: align README + OpenAPI metadata with the rest of the stack by @FireBall1725 in #17
- chore: bootstrap golangci-lint + tests for the security middleware by @FireBall1725 in #18
- chore(docs): theme /api/docs with Scalar's purple preset + brand indigo by @FireBall1725 in #19
- feat(imports): import user-interaction fields (rating, review, status, dates) by @FireBall1725 in #20
- Admin set-password endpoint by @FireBall1725 in #22
- Filter cover-batch candidates to books that need a cover by @FireBall1725 in #23
Full Changelog: v26.4.1...v26.4.2