Security fixes:
- Remove hardcoded MongoDB credentials from server.js (fail fast in production)
- Add OAuth state parameter validation for CSRF protection
- Add input validation for unitCode parameter to prevent NoSQL injection
- Add isValidUnitCode helper function
Deployment:
- Update docker-compose.yml to use env_file and environment variables
- Create .env.example with all required configuration variables