- Guard isolation covers audience, secret, refresh, blacklist, and reset cutoff. - The mounted admin route table must carry the backend guard. - Fresh PostgreSQL migrate and rollback keep framework and plugin histories apart.
- Commands hash with bcrypt, validate role codes, and revoke tokens on reset - Generated app main appends cabana.RuntimeCommands exactly once
- Fresh migrate is missing tokens_valid_after and the admin blacklist table - Reapplying the seed is not idempotent and role codes reject Winter duplicates