Login with JWT access + refresh tokens
User story
As a student, I want to log in securely with my email and password, so that my session stays active without logging in again every time.
Acceptance criteria
- Login form matches the Figma frame "Login – Mobile"
- On success, API returns a 15-minute access token and a 7-day refresh token
- Refresh token stored in an httpOnly cookie, never in localStorage
- Access token auto-refreshes silently before expiry
- Wrong password shows an inline error; 5 failed attempts lock the account for 10 minutes
- Unit tests for the auth service; API tests for /login and /refresh