Expected Findings
- All sensitive endpoints require authentication and return 401 without it.
- Cookies are set HttpOnly, Secure, and SameSite=Lax.
- Responses include CSP, HSTS, X-Frame-Options, and X-Content-Type-Options.
- No secrets, debug data, or stack traces are returned to clients.