Reverses the "single active profile, OIDC is access-only" decision from
2026-07-24 now that login needs to map each user to their own dataset
instead of a shared singleton.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Adds an access-gate authentication design: Keycloak OIDC via a
backend-driven Authorization Code flow, restricted by realm role,
with geniusrun minting its own session cookie. No data model or
multi-profile changes.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>