Main coves client

feat: add CovesAuthService for backend-delegated OAuth master

New authentication service that delegates OAuth complexity to the Coves backend. Instead of managing DPoP keys, PKCE, and token exchange client-side, the backend handles everything and returns sealed tokens. Key features: - Browser-based OAuth via flutter_web_auth_2 - Secure token storage per environment (prevents cross-env token reuse) - Mutex pattern for concurrent token refresh handling - Handle/DID validation with Bluesky profile URL extraction - Singleton pattern with test instance creation The backend's /oauth/mobile/login endpoint handles: - Handle → DID resolution - PDS discovery - PKCE/DPoP key generation - Token exchange and sealing (AES-256-GCM) 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>