Coves frontend - a photon fork

chore(prod): pre-launch hardening and de-Photonization pass master

Pre-production checklist sweep across two rounds, then a six-stream multi-model review (4 Claude specialty agents + GPT-5.6 + Kimi K3); all confirmed findings addressed. Security hardening: - Select.svelte: replace {@html option.label} with text interpolation (mutation-XSS landmine in a shared primitive; labels sourced from innerText). svelte/no-at-html-tags is now an ESLint error, with justified disables on the two safe uses (static SVG, DiceBear). - /api/proxy: CSRF origin validation on all state-changing methods via enforceSameOrigin() in validate.ts — exported so tests exercise the shipped gate, not a test-local mirror. New tests incl. Origin:"null". - /util/* debug routes: 404 in production at both layers (universal +layout.ts guard + hooks.server.ts edge check). - hooks.client.ts: log the full error, return only the sanitized message (was: raw error shown to users, nothing logged). - theme.svelte.ts: guarded JSON.parse of localStorage with per-entry theme validation — corrupted or garbage values (incl. themes:[null]) fall back to presets instead of white-screening every visit. - CSP: base-uri/object-src/frame-ancestors added in svelte.config.js and the backend Caddyfile (which replaces this header in prod; the frontend carve-out is documented there for deploy time). - instance.svelte.ts: exempt `building` from the PUBLIC_INSTANCE_URL fail-fast so image builds succeed; runtime guarantee unchanged. Dockerfile/CI: - node:22-alpine multi-stage (EOL alpine:3.14 dropped), pinned pnpm@10.28.2 with --frozen-lockfile, pnpm prune --prod, NODE_ENV=production, non-root user, HEALTHCHECK against a new dependency-free /healthz endpoint, documented runtime env contract (ORIGIN, PUBLIC_INSTANCE_URL, PUBLIC_INTERNAL_INSTANCE). - bun build path removed entirely (bun.lock, adapter, bunstart, CI target); pnpm-lock.yaml is the single lockfile and CI publishes the node image as the primary tag. - .dockerignore: fix Dockerile* typo, exclude .env*. De-Photonization: - PWA manifest installs as "Coves" with crab-mascot icons (any + maskable); Photon hexagon logos, stale favicon.png, and Photon-era PWA screenshots deleted; app.html favicon/splash use the mascot. - PUBLIC_XYLIGHT_MODE donation/source UI removed. - ~97 orphaned i18n keys removed across 21 locales; residual Photon brand strings in ar/et locale values renamed to Coves. - /translators page removed; package renamed kelp-coves -> coves-frontend; root README switched to the pnpm workflow. Documented decisions: - PUBLIC_SSR_ENABLED stays unset (CSR-only) until the cross-request locale race and logged-in hydration flicker are fixed (.github/README.md; tracked in the issues backlog). - Production sourcemaps deliberately kept (vite.config.ts). Tests: 673 passing (17 new: theme corruption recovery, /util gate, proxy CSRF, Origin:"null"). Verified: pnpm check clean, Docker image builds, boots healthy, /healthz 200, /util 404 in prod container. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>