- GET /api/graphics-elements no longer side-effects; refresh moved to
POST /api/graphics-elements/refresh (204), closing a CSRF vector on a GET.
- PrepareTroubleshootingPlaybackHandler now returns a typed LockedError from
both atomic lock-acquire failures; ApiResults.ToErrorResult maps it to 409
instead of falling through to 422, so a lock lost in the race between the
controller's pre-check and the handler's atomic acquire still reports 409.
- AuthController.MachineKey sets Cache-Control: no-store + Pragma: no-cache
on the 200 response carrying the master API key.
- Reworded the stale "subtitleId query parameter" endpoint description now
that playback/start takes a JSON body.
- Regenerated openapi/v1.json + docs/endpoint-index.md; docs/api-conventions.md
updated with the LockedError pattern (§3a) and the ToErrorResult table row.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>