Staff Sign-in

Admin / staff login (JWT + RBAC). Demo: admin / admin123. Auth is enforced only when the API runs with AUTH_ENABLED=true.