Dev login

No OAuth here. Picking a user just sets an unsigned dummy_session cookie holding that user's id. Enough to exercise role checks; not real auth.