85ba992432
- server.js: Node HTTP server with all API routes, static file serving, SPA fallback - Path traversal protection on static file serving - Async handler wrapped with .catch() to prevent unhandled rejections - readBody: size limit (1MB) + error handler - letter validation: single [A-Z] char check on progress/mnemonics routes - phrase length limit (500 chars) on POST /api/mnemonics - requireAdmin reads ADMIN_PASSWORD at request time for testability - logout uses session.token from requireAuth (not re-read from header) - 51 server tests passing (auth, progress, admin routes + edge cases) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>