Add sensitiveRouteMiddleware that blocks /api/v1/config, /api/v1/tailscale/status, /api/v1/tailscale/devices, /api/v1/updates/available when TOTP is disabled and the request comes from a non-Tailscale IP. This prevents infrastructure detail leaks on internet-exposed deployments. Verified on test.dashcaddy.net: all 3 routes now return 403.