- Introduced `OAuth2 API Tester` (HTML+JS) in `/tools`.
- Updated security configuration:
- Added comprehensive CORS configurations for OAuth endpoints.
- Enhanced CSRF handling to exclude `/oauth2/token`.
- Adjusted role handling to ensure case-insensitivity.
- Fixed `RIGHT-MANAGEMENT` role in `UserController`.
- Replaced logo asset in frontend.