feat: add iOS native OAuth client and local CSRF patch
Register grain-native://app OAuth client for iOS and add
grain://oauth/callback redirect URI. Patch PDS CSRF cookie
to drop Secure flag for local ASWebAuthenticationSession dev.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>