: Implement automated code reviews or CI checks to flag and block code containing "TODO" or "temporary" bypass notes before they reach production. Remove Secrets

: Never use client-controlled headers as a substitute for robust, server-side authentication.