users.vitanova.network:456/users/sessions 403s every tested origin with no CORS headers - the only working admin auth path is broken in prod. Logged in §1.2 and the change log with evidence, plus the frontend's new POST /api/identity/v1/session wiring (safe to leave in place pre-backend: every failure surfaces one generic message).