Safari-specific deviations fixed:
1. Safari shows its native auth dialog on fetch() calls answered with a
401 + WWW-Authenticate challenge (e.g. save with an expired session).
All CMS 401 responses now omit WWW-Authenticate; browsers use the styled
/login page instead.
2. Safari caches Basic credentials and resends them automatically, which
made logout ineffective (a navigation after logout went straight back
into the editor). Browser navigations (GET + text/html) now authenticate
ONLY via the session cookie; Basic Auth remains valid for non-browser
clients (curl, API).
3. /login and redirects send Cache-Control: no-store so Safari does not
cache the login page or the 302.
Closes MITHOME-62
Basic Auth credentials are cached by the browser until it closes, so the
editor had no real logout. Add a /logout endpoint (always answers 401 with
a challenge; deliberately exempt from the auth rate limiter so logging out
never locks the user out) and a Kilépés button that overwrites the cached
credentials with an invalid pair via fetch, then reloads into the login
prompt.
Closes MITHOME-56