Harden Pascal host authentication
- Uses a configured Pascal origin for OAuth redirects, mutation checks, and secure cookies instead of forwarded request headers.
- Fails closed when the host does not provide a trusted origin.
- Adds verified compatibility with Pascal 1.0.0-beta.4 and a bounded prerelease peer range.