Cover was named in the Series entry but never defined, and the gap is
what #47 is: nothing said whether a Cover is an address on a Site or an
image a Reader's browser can actually display. Kagane proved they are
not the same thing.
The ADR records the decision that follows — the backend fetches, stores
and serves every Site's cover bytes — along with the alternatives that
were rejected and the two knowing relaxations: destination-class control
instead of the host allowlist fetchableSeriesURL sets as precedent, and
a public cover route where the kagane proxy is session-gated.