* fix(randId): use crypto.getRandomValues for connection IDs
Math.random() gives ~30 bits of entropy and no cryptographic guarantees.
Switch to crypto.getRandomValues over a Uint32 buffer so device / saved-
connection IDs get full 32-bit range and don't collide across concurrent
transports.
Closes#1273
* fix: assert Uint32Array index for strict TS7 compat
Under strict + noUncheckedIndexedAccess (TS7 default), buf[0] is
number | undefined. Uint32Array(1) guarantees length 1, so assert
non-null to satisfy the number return type.