700de20225
Security review found the route's old default handed the TLS fetcher to any unrecognised site string; unreachable today because the shared read gates first, but a trap for a future caller that skips the gate. Returns nil now, matching the registry's zero-entry handling and the function's own docstring. Review's log-injection finding (unquoted series_url in read.go error wraps) was verified against Go's url.Parse and does not hold: control characters are rejected anywhere in the URL, so a client-supplied value reaching the log cannot carry a newline.