Replicates the admin-panel OIDC pattern: redirect/callback/token exchange
(client_secret_post) / JWKS validate / signed session cookie. get_user_identity()
prefers the OIDC session and falls back to the proxyAuth header. Adds /logout
route (was previously only a link). No manifest change yet.