Implemented foundations
The current application uses provider-neutral account entry, server-managed opaque sessions and request-integrity protections. Existing protected resources are designed around organisation and resource ownership, while browser-facing auth failures remain bounded and avoid returning provider secrets.