Replicates the admin-panel OIDC pattern: redirect/callback/token exchange (client_secret_post) / JWKS validate / signed session cookie. get_user_identity() prefers the OIDC session and falls back to the proxyAuth header. Adds /logout route (was previously only a link). No manifest change yet.