Both hosts now apply the same Identity password rule: at least 6 characters
with one uppercase letter, one number and one special character. Change
password requires an authenticated caller, verifies the current password
before evaluating the new one, and reports a policy rejection separately
from a wrong current password.
* Align EntityFrameworkCore.SqlServer and Tools to 8.0.8
* Add calendar/events backend API
Cherry-picked from main-backup (19994ef); scratch notes file removed.
* Require authentication on CalendarController
Security review found [Authorize] commented out, leaving all 6 calendar
endpoints anonymous. Enforce auth to match the API convention (17/23
controllers).
* Add CalendarController unit tests (xUnit + EF InMemory)