"""Security headers on every response (phase 82 — security audit SEC-04). Audit basis (SEC-04, severity Medium): no response in the app carried ``Content-Security-Policy``, ``X-Frame-Options``, or ``X-Content-Type-Options``. Every page — including the admin sign-in and the admin-only views — could be embedded in a third-party page's iframe: a malicious LAN page could overlay the admin UI and trick the signed-in owner into clicking Sync / Revoke / Delete-source actions (audit PoC: ``