- chatHub broadcasts room danmaku over SSE; new subscribers replay the
last N messages on join so they don't face an empty room.
- Add a host-only external push endpoint POST /api/room/{room}/broadcast
(requires room:publish, Bearer token) that marks messages host:true.
- Slide-window rate limiter (room+sender+IP, 5 per 3s) guards both the
public chat and the broadcast endpoint.
- Wire RBAC room:chat policy, SPA routing and the room-creation route.
Replace the legacy vanilla HTML/CSS/JS pages with a SolidJS single-page
app (TanStack Router/Query, Ark UI, Tailwind v4) and embed its build
output into the Go binary via //go:embed. SPA routes fall back to
index.html. Includes the room chat/danmaku panel, color picker and
broadcaster overlay on the watch/publish pages. Add web/node_modules
and local data to .gitignore.