== RED-PROOF R-135: validateCSRF returns true when there is no cookie (pre-v0.135.0)
--- FAIL: TestR135_BasicAuthWithoutHeaderIsRefused (3.41s)
    r135_csrf_test.go:92: POST /configuration with Basic auth and no X-Felhom-Operator header: 303, want 403
    r135_csrf_test.go:92: POST /apps/demo/reset-telemetry with Basic auth and no X-Felhom-Operator header: 303, want 403
    r135_csrf_test.go:92: POST /apps/demo/dismiss-issues with Basic auth and no X-Felhom-Operator header: 400, want 403
    r135_csrf_test.go:92: POST /offsite/endpoints with Basic auth and no X-Felhom-Operator header: 400, want 403
    r135_csrf_test.go:92: POST /offsite/endpoints/1/delete with Basic auth and no X-Felhom-Operator header: 404, want 403
    r135_csrf_test.go:92: POST /appliances/1/bind with Basic auth and no X-Felhom-Operator header: 400, want 403
    r135_csrf_test.go:92: POST /appliances/1/discard with Basic auth and no X-Felhom-Operator header: 409, want 403
    r135_csrf_test.go:92: POST /hosts/h1/delete with Basic auth and no X-Felhom-Operator header: 404, want 403
    r135_csrf_test.go:92: POST /hosts/h1/reveal-recovery-credential with Basic auth and no X-Felhom-Operator header: 404, want 403
    r135_csrf_test.go:92: POST /hosts/h1/request-logs with Basic auth and no X-Felhom-Operator header: 404, want 403
    r135_csrf_test.go:92: POST /customers/c1/block with Basic auth and no X-Felhom-Operator header: 404, want 403
rc=1

== restored
ok  	gitea.dooplex.hu/admin/felhom-hub/internal/web	(cached)
convicted routes: 39
