refactor: dedup OAuth sign-in flow + session profile into shared hooks (#62) master
Three components independently reimplemented the same two-step OAuth sign-in state machine — SessionMenu (nav dropdown), SessionPanel (compact header) and SignInPanel (record action row) — each carrying a byte-identical copy of the scope-submit handler (remember-return-path → signIn, with the same busy/error handling). The two session components also duplicated the keyed-by-DID profile loader. Extract both into shared hooks so the auth path lives in one place: - useSignInFlow(initialStep) owns step/pendingAccount/busy/error and the proceedToScopes / backToHandle / submitScopes / reset transitions. - useSessionProfile(did) owns the keyed-by-DID profile fetch. Behaviour-preserving: the moved logic is verbatim; each call site keeps its own input value and shell. SessionPanel keeps its 'idle' step and its handle-step back-to-idle transition via the raw setter. Verified with an adversarial line-by-line review against the pre-refactor files plus tsc, eslint (warning-neutral) and next build. Claude-Session: https://claude.ai/code/session_01DF1WX7iG9AL7FVXVbmmPNo Co-authored-by: Claude <noreply@anthropic.com>