# Remaining Security Issues 1. **No rate limiting on `/reauth`** — brute-force possible via export dialog 2. **No Content Security Policy (CSP)** header — XSS could leak crypto key from sessionStorage 3. **Crypto key in sessionStorage (extractable)** — necessary for refresh persistence, but XSS can steal it. HttpOnly cookie + service worker is more secure but complex 4. **No session rotation** — same token until logout; if leaked, valid for 24h 5. **No 2FA** — opted out of TOTP implementation 6. **Password generator modulo bias** — `c.charAt(arr[i] % c.length)` has slight bias when c.length does not divide 2^32; not practically exploitable