users.vitanova.network:456/users/sessions 403s every tested origin with
no CORS headers - the only working admin auth path is broken in prod.
Logged in §1.2 and the change log with evidence, plus the frontend's new
POST /api/identity/v1/session wiring (safe to leave in place pre-backend:
every failure surfaces one generic message).