Authentication entry
Use email and password, or GitHub login when Supabase OAuth is configured.
Preview auth is active because Supabase env vars are not configured. It uses an HTTP-only cookie for local MVP verification. Production deployments should set Supabase Auth env vars and use real provider sessions.