* Gateway WS: add unauthorized flood guard primitive * Gateway WS: close repeated unauthorized post-handshake request floods * Gateway WS: test unauthorized flood guard behavior * Changelog: note gateway WS unauthorized flood guard hardening * Update CHANGELOG.md