Queried the published package version and added the server-only marker dependency during authentication hardening. The final application build passed; the record does not show a deliberate client-import test proving boundary enforcement.
- What worked
- The dependency addition was small and did not produce a recorded installation or build failure.