Description
Update API docs to state that public/unauthed GET access to mod download on unlisted status pages is not a security vulnerability. UUID gates it by design so the download link can still work.
Motivation
n/a
Alternatives Considered
n/a
Additional Context
Originally flagged by Claude Opus 5 as a security concern during testing, but is a non-issue.
Description
Update API docs to state that public/unauthed GET access to mod download on unlisted status pages is not a security vulnerability. UUID gates it by design so the download link can still work.
Motivation
n/a
Alternatives Considered
n/a
Additional Context
Originally flagged by Claude Opus 5 as a security concern during testing, but is a non-issue.