- ecosystem.config.cjs: NODE_ENV was hardcoded to "development" even for the
production pm2 process, silently disabling every isDevEnv()-gated security
check (API key bypass, admin auth bypass) in production. Now "production".
- Restrict CORS via configurable CORS_ALLOWED_ORIGINS (falls back to allow-all
with a warning when unset, so this doesn't break existing traffic on deploy).
- Add an in-process, dependency-free rate limiter on /createtransaksi,
/api/payment-links, /api/payments/charge, and /api/payments/snap/token to
curb bot abuse / card-testing on endpoints the browser checkout must be able
to call directly (an API-key gate would break that legitimate flow).
- Auto-delete LOGS_*.log files older than LOG_RETENTION_DAYS (default 30).
- Persist activeOrders, notifiedOrders, orderRetryCount, and orderMerchantId to
server/data/state.json via Proxy-wrapped Map/Set (schedulePersist on every
mutation), so idempotency and retry-suffix tracking survive restarts/crashes
instead of resetting to empty every deploy.
- Remove processPaymentCompletion, dead code with no call sites.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>