- serve /favicon.ico outside session middleware so it loads on the login
page too (was 404 via the catch-all -> requireSession redirect)
- add embedded internal/server/static/favicon.ico (monitor icon) and
<link rel=icon> on the login page and vnc.html
- in vnc.html wrap console.error before importing core/rfb.js to drop only
the harmless 'noVNC requires a secure context (TLS). Expect crashes!' line
(plain VNC-password auth uses pure-JS DES, not crypto.subtle); reword the
now-redundant disconnect hint
- update AGENTS.md with the favicon route and the secure-context note
- run.bat: call scripts/ensure-vnc-password.ps1 so the password typed once
also sets the UltraVNC service VNC password (UAC only when it differs);
skip --spawn when 5900 is already taken (don't launch a 2nd winvnc).
- scripts/ensure-vnc-password.ps1: new - compares the password against
%ProgramData%\UltraVNC\ultravnc.ini (reverse-engineered UltraVNC DES
obfuscation) and only writes+restarts the service when it differs.
- scripts/set-vnc-password.bat: set UltraVNC service VNC password as admin
(createpassword/setpasswd + verify, GUI fallback). Manual fallback.
- internal/server/static/vnc.html: don't let the generic 'disconnect'
banner overwrite the specific 'securityfailure' reason (noVNC's
disconnect event has no reason field, so it always said 'unknown').
- AGENTS.md: document the above (scripts, run.bat, UltraVNC service note).