- Replace isomorphic-dompurify with xss to avoid ESM-only transitive
dependencies (jsdom/htmlparser2) that break the existing Jest test suite.
- Sanitize rendered docs and Terms-of-Service HTML via xss() in routes/docs.js
and routes/index.js.
- Remove full-object new-user logging from models/user_ldap.js and reduce
login-path error output to error.name/error.message only.
Co-Authored-By: Claude <noreply@anthropic.com>