Lets the admin restrict which pubkeys may log in, enforced server-side at /api/auth/login before a session is issued. Disabled by default; the admin and the bootstrap (no-admin-claimed-yet) case always pass. Manageable via the existing settings UI/API (npub or hex, one per line). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>