v1.27.2         Tp-Note v1.27.2

    Breaking config change:
    - viewer.same_user_policy: the value "Reject" is renamed to "Enforce";
      an existing tpnote.toml using "Reject" now fails to parse and must be
      updated. The field name, the "Off" value, and the feature itself are
      unchanged.

    Features:
    - Auto-generate heading ids (tmpl_html.auto_heading_ids) so a table of
      contents or cross-reference works without hand-written anchors, and the
      same note keeps navigating correctly when rendered by GitHub or GitLab
      instead of Tp-Note. Selectable slug algorithm: "Gfm" (default, matches
      GitHub/GitLab), "Pandoc" (matches Pandoc's auto_identifiers), or "Off".
      An explicit {#id} always wins.

    Fixes:
    - Same-document fragment links (#ch1) are now rebased onto the note's
      directory correctly, instead of being treated as a filename and
      concatenated onto the note's directory, which broke
      --export-link-rewriting=short|long and could 404 or silently swap
      documents in the viewer.

    Viewer:
    - Merge the two peer-rejection 403 pages (different OS user vs.
      undeterminable OS user) into one, naming both peer and local users and
      offering the two remedies (a non-sandboxed browser, or disabling
      same_user_policy) inline.
    - Log the 403 refusal reason before writing the response, not after, so
      it isn't lost when the peer already dropped the connection.
    - Relax the default viewer.displayed_tpnote_count_max from 20 to 1000,
      now that the viewer also binds to the first browser, checks the Host
      header, and checks the peer OS user.

    Config:
    - Drop Flatpak browsers from the default fallback-browser list (they are
      sandboxed and fail the same-user check by default); documented as a
      manual opt-in example instead.

    Dependencies:
    - Update tpnote-lib to 0.46.9.

    Docs:
    - Remove stale NetBSD/pkgsrc install instructions.
    - Separate Nix cross build instructions from the standard rustup/cargo
      build; mention the Windows MSI packaging script.