Native Auth Helpers For gh-forgejo-shim

Added a first-party auth command group so Forgejo tokens can be validated once, stored durably, and reused by Terminal and GUI-launched tools without depending on shell-only environment variables.

ScopeAuth storage, CLI commands, Forgejo validation, doctor/bootstrap messaging, docs, tests.
Issuegh-forgejo-shim-oap
Validation82 unit tests, compileall, CLI auth smoke checks, and whitespace checks passed.

Summary

Implemented gh-forgejo-shim auth login/import/status/logout. Login and import validate tokens with Forgejo, save them in shim-owned storage, and add the host to the allowlist so routed gh pr, gh issue, and gh repo commands can use the token from GUI-launched apps.

Changes Made

Context

Before this change, the shim could find tokens from env vars and a few existing Forgejo CLI config files, but it could not manage its own auth. That left GUI-launched apps such as Codex dependent on inherited shell state or unrelated tool config. The new commands make auth a direct shim setup step.

Important Implementation Details

Relevant Diff Snippets

This intentionally excerpted, server-rendered patch shows the core auth storage and CLI surfaces. The full diff also includes docs and test coverage.

Expected Impact for End-Users

Users can run gh-forgejo-shim auth login git.example.com once, restart GUI tools if needed, and then use normal GitHub-style commands such as gh pr view, gh pr create, and gh pr status in Forgejo repositories without exporting tokens into each shell or app launch environment.

Validation

Issues, Limitations, and Mitigations

Follow-up Work

No required follow-up issue was filed for this turn. A future enhancement could add explicit validation URL options for HTTP-only or self-signed local Forgejo instances if users run into that environment.