- Add passport, passport-google-oauth20, jsonwebtoken, cookie-parser, uuid deps
- Create config/auth.js with JWT, cookie, and OAuth configuration
- Create models/user.js with MongoDB user model and indexes
- Create middleware/passport.js with Google OAuth strategy
- Create middleware/auth.js with requireAuth middleware and sliding window refresh
- Create routes/auth.js with OAuth flow endpoints
- Update server.js to integrate auth, protect all data endpoints (except /health)
- Configure CORS for cookie-based authentication