The notification service's httpx client was the only outbound client in
the codebase still leaking python-httpx/<version> as User-Agent; all
other clients identify as Bambuddy/1.0 since the May 2026 compliance
pass. Bring it in line.
The reporter's ntfy server was behind a Cloudflare Tunnel and CF returned
its JS challenge page (Just a moment...) to every API request — confirmed
by reproducing the same 403 with curl. Cloudflare can't be solved from a
backend, so add detection for the challenge shape (Server: cloudflare or
cf-mitigated header, or <!DOCTYPE html>...Just a moment... body) and
return an actionable error message that points at the real fix on the
user's CF side instead of dumping the raw HTML.
Normal 403s (auth failures with plain text bodies) still surface the
original body so genuine errors stay debuggable.