Main coves client

test(maestro): cover the OAuth cancel redirect (a4) and update a3 master

a3's cancel branch asserted the old backend dead-end ("OAuth callback failed" page + manual Close tab); the backend now redirects the error back into the app, so assert the quiet "Sign in cancelled." snackbar on the login screen instead. New a4_oauth_cancel denies the authorization on the PDS consent page ("Deny access") and asserts the same graceful return. Runs last in the suite (starts and ends signed out, after a3). Quirk documented in the flow: Chrome's "Save password?" sheet floats over the consent page but does not cover the buttons — tap through it, never BACK (closes the tab). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>