feat(oauth): add web frontend dev proxy and generalize redirect URI handling master
Refactors the mobile-only OAuth redirect URI system into a configurable allowlist that supports both mobile apps (custom schemes + Universal Links) and web clients (HTTPS redirects). Adds Caddy-based reverse proxy for web frontend development, enabling same-origin cookie sharing between Vite frontend and Coves backend. Changes: - Refactor isAllowedMobileRedirectURI() into OAuthHandler.isAllowedRedirectURI() with BuildAllowedRedirectURIs() builder for the configurable allowlist - Add smart redirect: HTTPS clients get direct HTTP redirect, custom scheme clients get the intermediate redirect page - Add Caddyfile.dev reverse proxy config (Vite :5173 + Coves :8081 on :8080) - Add scripts/web-dev-run.sh for combined backend+frontend dev startup - Add Makefile targets: run-web, web-proxy, web-proxy-bg, web-proxy-stop - Auto-run db-migrate before server start in make run and make run-web - Update OAuth client comments to clarify ATProto loopback client_id spec - Add PAR request debug logging in dev auth resolver - Update all security tests to use OAuthHandler instance methods Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>