Coves frontend - a photon fork

refactor(auth): simplify session management by delegating to Go backend master

Previously, the frontend maintained its own encrypted session store (kelp_session) with AES-256-GCM, managing account lists, active account switching, and re-validating credentials locally. This duplicated auth logic that the Go backend already handles. The new model is stateless on the frontend: - The Go backend sets `coves_session` (an opaque cookie) during OAuth - hooks.server.ts validates every request by calling /api/me - The frontend stores no user data locally — auth state comes entirely from the server's response to /api/me Changes: - Remove AES-256-GCM session crypto (session.ts, cookies.ts) - Simplify OAuth callback to just validate CSRF state and redirect - Delete multi-account switch endpoint (/api/auth/switch) - Rewrite hooks.server.ts to fetch /api/me with typed error handling (network_error vs validation_error) and sessionExpired signaling - Add authError and sessionExpired to locals/PageData types - Simplify auth.svelte.ts: remove switchTo(), single-account syncFromServer() - Update proxy to read authToken from flattened locals.auth.authToken - Rename postform.svelte.ts -> post-form.svelte.ts Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>