7d0eaaef02
Adds sessionKey/signSession/verifySession primitives and setSessionCookie/clearSessionCookie helpers in a new backend/session.go. Sessions are derived from API_TOKEN via HMAC-SHA256 with domain separation (sessionKeyPurpose), so there is no session table and rotating the token invalidates every outstanding cookie at once. No routes or handlers yet — that's task 5.