fix(auth): enforce instance lock server-side, drop stale profile on unauthenticated sync master
- POST /api/auth/login now returns 403 for any origin other than PUBLIC_INSTANCE_URL when PUBLIC_LOCK_TO_INSTANCE is on (the default). The flag previously only hid the instance field in the login UI, so the endpoint could still start OAuth against an arbitrary host. Policy lives in a pure lockedInstanceOrigin() helper shared by the browser (LINKED_INSTANCE_URL) and server. - Profile.syncFromServer() now resets to guest when the server reports no session, instead of leaving a previously persisted authenticated profile in localStorage. A shared device no longer keeps showing the prior user's handle/avatar after their cookie expires. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>