Phase 1 foundation: - DB: users table extended (password_hash, is_active, login_attempts, locked_until) - DB: user_oauth_tokens table (user_id, provider, access_token, refresh_token) - password_utils.py: SHA-256+salt hashing, verify, rate-limit lock check - auth.py: POST /auth/register + POST /auth/local-login + /auth/login?provider=local - Login page: tabs Login/Register with Gitea OAuth button - settings.html: profile (name/password), forges, API tokens, sessions - ALTER TABLE migrations for existing DBs