# Changelog - FlowDeck ## v7.3.6 (2026-09-30) — Audit sécurité : A19 terminé (aucun préfixe cookie-auth exempt) ### Fixed - **A19 (fin)** — les 46 appels non-GET restants des 5 derniers préfixes (`/api/agent`, `/api/settings`, `/api/local-workspace`, `/api/gitea`, `/api/workspace` + `/api/workspaces`) reçoivent `X-CSRF-Token` (expression cookie en ligne, portée indifférente fonction/Alpine/attribut) ; les 5 préfixes sortent d'`EXCLUDED_PATHS` - Vérification syntaxe : les `