Added get_current_user_or_forward_auth() combined dependency that: - First checks for X-authentik-* headers from NPM forward auth (web) - Falls back to JWT Bearer token validation (mobile/native) This fixes web authentication where browsers don't send Bearer tokens but rely on NPM's forward auth proxy to pass user info via headers. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>