docs: document the QUERY shape rules and webhook verb handling
Analyzer-Rules gains ATC_API_OPR028 and ATC_API_OPR029 - a QUERY with no
requestBody is a GET with a less widely understood verb, and a QUERY declaring
201/409 contradicts the safe/idempotent contract that lets callers and caches
retry it freely.
Working-with-OpenAPI now summarises all three build-time rules in one table,
notes that webhooks honour the declared verb, and records that streaming over
QUERY is buffered rather than streamed. Working-with-Webhooks shows the
MapMethods form for a non-standard verb.
Roadmap marks the webhook fix and the two new rules as shipped, and records the
two deliberately declined items - streaming over QUERY and an
X-HTTP-Method-Override fallback - so the reasoning is not rediscovered later.
docs: update Development-Notes.md extractor table from 10 to 45+ entries
Expanded the extractor table to document all extractors organized by category:
- Core extractors (15): Schema, Enum, Handler, Endpoint, Result, etc.
- DI & cross-cutting (15): Security, RateLimit, Resilience, Cache, Versioning
- OAuth/OIDC (7): Config, DI, Handler, Options, TokenProvider
- Webhook (5): Handler, Endpoint, Parameter, Result, DI
- Shared utilities (4): CustomErrorResponse, ApiOptions, WebAppExtensions