BI L2 scoped access — phase 2 (based on dashboard-project1mehr.zip + BI-L2-users-columns-patch-v1.zip)

This is a staging/QA patch, NOT a complete production-ready customer release.

WHAT IS INCLUDED
- The prior BI.Users-column-aware auth/login/KPI/lookup patch, merged with the additional scoped endpoints.
- 28 additional reporting and export APIs now apply a category condition before aggregation.
- For hybrid accounts, non-audited routes that pass through auth_user() fail closed with HTTP 403.
- The existing token issuance and Role values are unchanged.
- Existing users with AllowedFullL1Ids=NULL and AllowedL2Ids=NULL retain legacy category scope.
- No CREATE/ALTER/DROP/DELETE SQL is included. No sale tables are modified.

CONFIRMED CUSTOMER SCOPE (data must be loaded in BI.Users only after acceptance testing)
CanAccessAllL1=0
AllowedL1Ids=1,3,4,6,8,10,11,12
AllowedFullL1Ids=3,10
AllowedL2Ids=13,14,21,43,46,47,57,59,74,79,102,104,107,108
CanCompareMarket=0

IMPORTANT LIMITATIONS
- The v1 brand-analytics and v1 reporting modules, holdings/JTI, certain selected-store product reports, AI and map analytics remain unsupported for granular accounts and may return 403. They require separate query-level remediation rather than leaking full-L1 data.
- Account should not be delivered to a customer before staging QA of every exposed route and DB aggregations.
- No live MSSQL integration tests were available; PHP syntax and pure helper regression tests are included.
- If the server has other local patches newer than dashboard-project1mehr.zip, diff before installing.
- As with all token-based restrictions, production config must have auth_enabled=true.

INSTALL IN STAGING FIRST
1. Back up the current C:\xampp\htdocs\dashboard-project directory and take a DB backup.
2. The two nullable columns AllowedFullL1Ids and AllowedL2Ids must already exist on BI.Users.
3. Extract the zip into C:\xampp\htdocs, merging the dashboard-project directory. This includes the previous v1 patch, whether or not it was installed earlier.
4. Run: C:\xampp\php\php.exe -l C:\xampp\htdocs\dashboard-project\src\helpers\Auth.php
5. Run: C:\xampp\php\php.exe C:\xampp\htdocs\dashboard-project\tests\L2HybridScopeRegression.php
6. Run: C:\xampp\php\php.exe C:\xampp\htdocs\dashboard-project\tests\L2EndpointGateRegression.php verified
7. Run: C:\xampp\php\php.exe C:\xampp\htdocs\dashboard-project\tests\L2EndpointGateRegression.php tobacco
8. Compare live API totals for an existing legacy user. Test granular account in staging for 403 on l1_id=5, allowed L2, unfiltered calls, product CSV and unsupported routes.

The regression scripts check the SQL predicate construction and route gate; they do not connect to production SQL Server.
