- sanitizer XSS serveur (markdown + page de partage) [BUG-021/022] - rate-limit/lockout MFA [BUG-023] - isolation vaults par segments [BUG-024] - caps regex ReDoS [BUG-025] - SSRF webhooks + secrets externalises [BUG-026] - rotation/revocation des jetons [BUG-027] - politique de mot de passe + invalidation sessions [BUG-028] - verrous users.json [BUG-029] - IP reelle dans les audits [BUG-030] - rate-limit par compte [BUG-031] - symlinks hors vault ignores [BUG-032] - recherche simple via inverted index [BUG-033] - token en memoire + cookie HttpOnly, CSP durcie [BUG-034] Tests: pytest 961 passed / 6 skipped, ruff 0, mypy 0, frontend vert.
Add 78 new tests targeting high-impact uncovered modules: - tests/test_search_advanced.py (23 tests): InvertedIndex CRUD, search/advanced_search/suggest functions, tag/title indexing - tests/test_indexer_advanced.py (15 tests): hooks, file CRUD, path index, lookup, generation counter - tests/test_modules.py (40 tests): audit, history, rate limit, saved searches, vault settings, webhooks, share Coverage improvements: ratelimit.py: 80% → 100% share.py: 24% → 97% saved_searches: 37% → 95% history.py: 26% → 86% audit.py: 0% → 85% search.py: 44% → 82% webhooks.py: 31% → 67% vault_settings: 31% → 69% indexer.py: 47% → 65% Overall: 35% → 49%