Security fixes: - Remove hardcoded MongoDB credentials from server.js (fail fast in production) - Add OAuth state parameter validation for CSRF protection - Add input validation for unitCode parameter to prevent NoSQL injection - Add isValidUnitCode helper function Deployment: - Update docker-compose.yml to use env_file and environment variables - Create .env.example with all required configuration variables