security: require verified email for admin + harden sessions
Admin (email allowlist) is now gated on a verified email and re-evaluated per request instead of trusting a frozen cookie flag; session max_age cut to 8h. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in: