d34b2645ee
App clients reach minerva only over HTTPS now: the Android cleartext policy blocks plain HTTP to minerva.lan, and the public Let's Encrypt cert on app.doctate.de chains to the system trust store, so no network-security-config change is needed. Update the profile template's SERVER_URL and comment to reflect the HTTPS convention. closes #7