* Lock dashboard login to GitHub org members
Add an org-membership gate to the dashboard OAuth callback. After
resolving the GitHub login, enforce_org_login_gate(login) checks the
existing ALLOWED_GITHUB_ORGS allowlist before issuing a session.
- Reuses ALLOWED_GITHUB_ORGS (no new config knob) and
is_user_active_org_member (installation-token check, so no extra
OAuth scope and private memberships are visible).
- Fail-open when unset/blank so existing deployments keep working;
fail-closed on API errors.
- Gate runs before the session cookie/token is persisted.
Adds unit tests and documents the behavior in INSTALLATION.md.
* docs: document Organization Members permission required for org login gate