Hands-on report of an authorized web pentest on a private BitTorrent tracker: Nuxt.js SSR + Node.js behind Cloudflare WAF. 3 findings (CORS, unbounded chat history, NUXT_DATA), Playwright trick for WebSockets, and what Cloudflare doesn't protect against.