- Updated OAuth2 password flow to return 401 Unauthorized with proper WWW‑Authenticate header.
- Added new SecurityScopes string and expanded security and general documentation, including Hypercorn, static files, templates, cookies, and response headers.
- Corrected documentation typos throughout.