1fb82f09b2
---ci--- project: orca phase: 6 milestone: v0.12 status: execute ---/ci--- Add KindOidc to ACL: OIDCClaims struct, OidcIdentity, OidcGroupIdentity, CheckOidc (checks user sub + group: prefix entries). KindToken now always denies (R-021: no Orca-issued tokens). Existing acl.json entries with KindToken are inert (P07 removes, P22 migrates). acl.json file mode tightened to 0600. Deny-by-default enforced. 4 new OIDC ACL tests + deprecation test. Existing tests migrated to KindOidc. All pass.