auth: replace username/password with Google login
Listeners (and the owner) now log in via Google instead of a local
username/password account. This lowers the barrier to commenting and
removes the home-built password/registration system.
- src/config/google.js: raw OAuth2 helpers (authorize/token/userinfo) via
the built-in fetch, config-driven. Boot keeps working without credentials.
- src/routes/auth.js: /auth/google + /auth/google/callback (find-or-create
user on email, ADMIN_EMAIL -> god, set session). login/register/reset POST
handlers removed; /login now shows the Google button.
- database.js: idempotent column users.google_sub.
- account.js + account.ejs: change-password removed.
- auth-login.ejs / welcome.ejs: Google button instead of password form.
- shared-styles.ejs: .btn-google styling.
- .env.example: GOOGLE_CLIENT_ID/SECRET/REDIRECT_URI + ADMIN_EMAIL.
Existing users are matched on email (owner retains their site).
DO NOT deploy to roboburr until the Google credentials are in .env, otherwise
the owner locks themselves out.
Co-Authored-By: Claude <noreply@…>