fix: harden admin actions, search, sanitization and repo hygiene
- Split approve/dismiss application workflows with distinct audit logs,
rate-limited guards and real error logging
- Validate article status/date/id input and stop resetting publishedAt
on every update
- Validate guild updates (state, forum enums, non-empty name) behind
rate-limited guard
- Fix scheduled-article publishing (ignore NULL dates, set updatedAt,
type-safe predicates)
- Harden admin search API (LIKE escaping, query cap, per-user
rate limit, round-robin result cap) and fix search dialog
abort/res.ok/loading races
- Lock down HTML sanitizer to an allowlist profile and add XSS tests
- Improve mobile nav accessibility (unique id, dialog role, focus
management, scroll lock, outside close)
- Log swallowed server errors instead of silent catch blocks
- Remove dead eslint config, drop unused dompurify deps, restore knip
CI step, add Playwright config with smoke spec