Authentication
Better Auth powers email/password, OAuth, sessions, verification, and role-aware access.
1. Use the Better Auth route handler for session, email/password, Google, and GitHub flows.
2. Keep proxy redirects as a UX guard and re-check authorization inside Server Components.
3. Persist roles on users and route admin-only workflows through requireAdmin.
4. Store linked OAuth accounts and verification tokens through Drizzle-backed tables.