fix: add auth checks on all GET endpoints, timing-safe comparisons, and XSS sanitization 1dc7696 Nyk commited on Feb 27