isValidAssetUrl() was rejecting bare filenames (e.g. "1234567890.webp") which is the established convention the frontend sends. Now accepts bare filenames while still blocking path traversal and unsafe schemes. Also updates client-side password validation to match server's 8-char minimum.