L-01: Add Cache-Control: no-store to all /api/ responses via nginx L-02: Validate ntfy_server_url against blocked networks at save time I-03: Add Permissions-Policy header to restrict unused browser APIs Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>