feat: add auth pages (login, logout, register, change-password)
Login uses loginLimiter, authenticates via authenticateUser, creates
session cookie, and redirects foster role to /foster, others to /admin.
Logout destroys session and redirects to /. Register uses
registrationLimiter, validates input, creates inactive user, and sends
registration notification. Change-password verifies current password,
enforces 8-char minimum, updates hash, clears mustChangePassword flag.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>