AI Summary: A security vulnerability exists in `backup_api.go` where a missing `X-Hive-Role` header defaults to 'owner', allowing unauthenticated users direct network access to download backups. This bypasses normal authentication checks, especially when the `authToken` is empty on spokes.
AI agent orchestration for open and closed source — a fully customizable fleet of AI agents covering every level of project maintenance, from brainstorming to full autonomy