Auth: web session (backend)
Theme and layout preferences already persist locally. Account and backend settings will use the existing web session auth model.
Next: Extend with authenticated preference APIs when needed.