Don’t be sorry! This is such a great write up! Thank you for sharing and I hope they realise how lucky they are that you properly disclosed BOTH vulnerabilities with a 30 days notice before public disclosure. I hope they will follow your advice, or else I believe this won’t be the last vuln of this scope to hit them if they chose to ignore good security practice!