Lets users authenticate ntfy notifications through a reverse proxy or tunnel
(Pangolin, Tailscale, ...) in front of the ntfy instance. Adds three optional,
backward-compatible settings that default to empty and are no-ops when unset:
- NTFY_URL_QUERY_STRING: appended to the request URL (e.g. p_token=...). A
leading '?' is tolerated, and the value is redacted from error logs / the
plugin result file since the request URL can carry a secret token.
- NTFY_CUSTOMHEADER_NAME / NTFY_CUSTOMHEADER_VALUE: a custom request header,
skipped with a warning if it would clobber a built-in header (e.g.
Authorization) so ntfy's own auth stays intact.
Secret-bearing fields are password-masked in the UI. Addresses #1663.