- consumeTransferToken now recomputes and constant-time compares the
entry's HMAC-SHA256; previously the signature was minted but never
checked, so the documented "防篡改" guarantee was hollow and security
rested solely on the sync.Map key's randomness.
- CSRF switches from a raw-random double-submit cookie to a signed token
(nonce.HMAC-SHA256 keyed by JWTSecretKey). The middleware now also
validates the signature, defeating sibling-subdomain cookie tossing
where a naive header==cookie pair would otherwise pass.
Co-authored-by: cloudcode <cloudcode@users.noreply.github.com>